
Lorenzo Maria Pacini
The EU has adopted a way of waging war against Russia that has transformed warfare and allowed for the experimentation with new hybrid approaches, but it has exposed the absurdity of the European system.
A Definition to Be Debunked
In 2023, Time magazine called the conflict in Ukraine "the first AI war." The phrase caught on, circulating in think tank reports, parliamentary hearings, and presentations by companies in the sector, and ultimately shaped the way European decision-makers envisioned their strategic position. Before building any analysis on it, however, we must ask whether it is true and, above all, try to understand what the European authorities'-on whom we will focus-objectives were regarding this hybrid war.
Let's start with the "no" camp. José Pardo de Santayana, in an analysis published by the Instituto Español de Estudios Estratégicos, observes that AI in Ukraine is an enabler rather than the defining element of the conflict: the war is being fought on the ground with infantry and artillery, in a manner more reminiscent of 1916 than any futuristic scenario, and territory is gained and lost in slow, grueling battles. Gulsanna Mamediieva, who has worked within Ukraine's digital transformation apparatus, is even more blunt: genuine autonomy-where the machine makes its own decisions on the battlefield-remains out of reach, and the term "autonomous" is commonly applied to platforms that operate on pre-programmed automation. Rakhmetov and Murzagulova, in their comparative study published in the *Journal of Strategic Security*, conclude that traditional methods of combat remain dominant and that AI serves primarily to enhance their effectiveness. We are talking about pro-Ukraine authors, not "Kremlin propagandists," as the Western media claim.
This correction is not mere terminological pedantry. The definition we adopt has specific political implications. If the war in Ukraine is the first AI war, then Europe is lagging behind a revolution that has already taken place and must catch up quickly by purchasing what it does not have time to develop. If, on the other hand, Ukraine is the laboratory where that war is being prepared, then Europe faces a window of opportunity for decision-making, and the question is not how quickly to bridge a gap but what capabilities to build and under what constraints. The first interpretation creates a sense of urgency; the second creates a choice. European institutions, as we shall see, have almost always acted according to the former.
It is worth noting the paradox that Fontes and Kamminga have articulated with a bluntness unusual in the specialized literature: every day that the conflict continues and human beings die, AI systems are trained with real data from a real battlefield-not to stop that suffering, but to fight the next war more effectively. The strategic value of the conflict in Ukraine for the European defense industry lies precisely in this: the availability of an authentic operational environment, with a symmetric adversary and active electronic warfare, which no simulation can replicate.
What Artificial Intelligence Is Actually Doing in Ukraine
Before examining the European response, we must determine-as precisely as open-source information allows-what AI is actually doing on the ground. The available academic and military literature points to five functions:
a) Geospatial intelligence and reconnaissance
This is the domain where the contribution of algorithms is most well-established. Neural networks combine ground-level photographs, drone footage, and satellite imagery to produce intelligence analyses faster than a human team can. Palantir's CEO has publicly admitted that his company is responsible for most of the target designation in Ukraine-tanks, artillery-thanks to timely information derived from satellites and social media. Planet Labs, BlackSky, and Maxar provide satellite imagery to the Ukrainian government and armed forces. Ukraine's advantage in geospatial intelligence, recognized by Western observers, is to a large extent a borrowed advantage.
b) Unmanned Systems
AI automates takeoff, landing, and target acquisition. According to Ukrainian sources, once the operator has selected and confirmed the target, the data is transferred to the battle management system, reducing the time to destruction to just over thirty seconds. The most significant function from a military standpoint, however, is another: resistance to electronic warfare. A drone capable of completing its mission when GPS and radio communications are jammed restores to the attacker a capability that Russian countermeasures had gradually eroded. It is this-and not decision-making autonomy-that is the technical reason for the commercial success of the European systems discussed below.
c) Information Warfare
Here, the symmetry is greater than the European public narrative would have us believe. Well-known examples include the deepfake video of Zelenskyy announcing surrender in March 2022, recordings attributed to Valeriy Zaluzhny calling for a coup, and chatbot networks (in 2022, Twitter removed approximately 75,000 fake accounts linked to bots identified as Russian). In March 2024, the CopyCop network used algorithms to rewrite news stories from reputable outlets, publishing over 19,000 articles on eleven websites within a few weeks. But Kyiv has also produced its own deepfakes-such as the April 2022 video showing a synthetic Putin visiting Mariupol-alongside fact-checking tools developed by startups like Osavul and Mantis Analytics. The operational distinction between the offensive and defensive use of generative AI-which European public discourse tends to equate with the distinction between the two belligerents-does not hold up on a technical level.
d) Facial Recognition
The war marked the first documented use of facial recognition in combat, Clearview AI, provided free of charge to Ukraine by a U.S. startup, was used for checks at checkpoints, identifying missing persons, reuniting refugees, and gathering evidence for the International Criminal Court. By November 2023, Ukrainian government representatives had analyzed two billion images from VKontakte, identifying over 230,000 individuals believed to be Russian military personnel or officials, with approximately 350,000 searches conducted over twenty months. This feature deserves special attention in a European discussion: it involves a technology whose indiscriminate use is classified by the AI Act as a prohibited practice in the civilian domain, yet it is being deployed on a massive scale in an operational theater funded by the European Union.
e) Logistics, mine clearance, training
The least visible aspect is probably the most extensive. AI-enhanced weapons systems are the tip of the iceberg, while the bulk of the technology is and will be deployed far from the battlefield-in planning, logistics, and predictive maintenance. The ICDS document signed by Vitaliy Goncharuk, a member of the Ukrainian Expert Committee on AI, lists among the revised priorities for 2023: scheduled maintenance; anticipating shortages in supply depots; unmanned logistics vehicles for resupply and the evacuation of the wounded; and the consolidation of heterogeneous data for the detection and neutralization of mines.
The European Union: The Regulator That Becomes a Buyer
Over the previous decade, the European Union had forged a distinct international identity in the digital sphere: that of a regulator. The GDPR, the Digital Services Act, the Digital Markets Act, and finally the AI Act formed a model in which Europe compensated for its industrial lag with an exportable regulatory capacity-the so-called "Brussels effect." The war in Ukraine has reversed this approach in the military domain, and the reversal occurred unintentionally, through the accumulation of separate decisions.
The European Defense Fund has a budget of 7.3 billion euros for the 2021-2027 period, of which 2.7 billion is earmarked for research and capability development. Since the regulation entered into force in May 2021, the Commission has committed nearly 6.5 billion euros in total, funding 224 projects and positioning itself among the world's leading investors in defense R&D. The 2026 work program, adopted on December 17, 2025, allocates 1 billion euros and includes among its priority areas the use of artificial intelligence and swarms of small robots and drones for tactical situational awareness. Prior to that, in April 2026, the Commission announced an investment of 1.07 billion in 57 new projects selected through the 2025 calls for proposals, involving 634 companies from 26 Member States and Norway, in sectors including artificial intelligence, cyber defense, drones, and anti-drone systems.
The most politically significant development concerns Ukraine's integration. With the support of the European Defense Innovation Office established in Kyiv, Ukrainian partners have been able to join some of the projects; the 2026 program also makes Ukrainian entities eligible for trickle-down funding. The STRATUS project, which is developing an AI-based cyberdefense system for drone swarms with the participation of a Ukrainian subcontractor, exemplifies this mechanism: operational experience gained in an active conflict is incorporated into the European industrial base. It is the exact opposite of aid: Ukraine is not merely a recipient of capabilities; it is a provider of knowledge.
Regulation (EU) 2024/1689 represents the world's most ambitious attempt to regulate artificial intelligence through a risk-based framework. In Article 2, paragraph 3, it excludes from its scope systems placed on the market, put into service, or used exclusively for military, defense, or national security purposes, regardless of the type of entity carrying out such activities, and specifies that this is without prejudice to national competences under Article 4, paragraph 2, of the Treaty on European Union. Recital 24 explicitly refers to public international law with regard to the use of lethal force.
This exclusion is not an oversight: it is the result of deliberate pressure from Member States, led by France, during the final stages of the trilogue. The rationale cited-that defense falls under national sovereignty-is consistent with the architecture of the treaties. The consequences, however, have been described in increasingly harsh terms. It has been noted that the Union has not equipped itself with any instrument to govern its own military AI, nor that of others; and when other actors operate in this space, European institutions are observers, not participants. The problem is exacerbated by the dual nature of the technology: as Justinas Lingevičius points out, the line between civilian and military AI is increasingly blurred, and dual-use systems are not expressly addressed by the regulation.
There is also an asymmetry that deserves to be clearly addressed. Facial recognition for the purpose of remote biometric identification is, in the European civilian sphere, one of the most strictly regulated practices; in the Ukrainian theater, it has been used to build databases of hundreds of thousands of individuals. The EU funds that theater of operations. This does not mean that Ukraine's decision is illegitimate-the suspension or relaxation of safeguards during a state of war is a matter of domestic and international law, not of European regulation-but it does mean that Europe is exporting technological capabilities into a context over which its own regulatory framework has no say. Goncharuk acknowledges this from the inside: the Ukrainian government has accumulated a considerable amount of information on its citizens, and questions remain regarding the retention and use of data after the war.
Since the regulation does not apply, European oversight of military AI takes a different route: funding conditions. The EDF regulation incorporates the requirement for meaningful human oversight as a condition for accessing research funds, and the European Parliament has repeatedly called-in 2018 and 2021-for an international ban on lethal autonomous systems lacking such oversight. The Parliament's position is based on three principles: maintaining human involvement in command and control, legal accountability of individuals and states, and promoting international governance through the United Nations, particularly within the framework of the Convention on Certain Conventional Weapons.
The weakness of this mechanism is structural and must be stated without leniency. The conditionality applies to those seeking European funds, not to those operating with national funds; and the bulk of European military spending is national. A Commission spokesperson has, moreover, precisely defined the scope of the institution: the EDF is a research and development tool for the defense industry, and goes no further than that. The result is that the Union has three layers of documentation-directly applicable regulations, non-binding strategic documents, and financial instruments with built-in conditionality-whose overlap creates the impression of comprehensive governance without actually delivering its substance.
National governments: capabilities without a framework
While the European level exhibits regulation without capabilities, the national level exhibits the symmetrical flaw.
The German case is the most instructive because it condenses all the tensions of the framework into a single industrial trajectory. Helsing SE, founded in Munich in 2021 by Torsten Reil, Gundbert Scherf, and Niklas Köhler, began as a developer of AI software for military applications before moving on to the design and production of autonomous systems. Its flagship product, the HX-2 loitering munition, weighs about twelve kilograms, costs around 17,500 euros, has a claimed range of one hundred kilometers, and is equipped with onboard AI that ensures its resistance to electronic warfare. Integrated into the Altra system, it can operate in coordinated swarms under the control of a single operator.
Deliveries to Ukraine began in late 2024. In February 2025, the company announced the production of 6,000 HX-2 units for Kyiv, following a previous order for 4,000 HF-1 drones manufactured in collaboration with the Ukrainian military-industrial complex. According to Scherf, the success rate of missions under combat conditions stands at around seventy percent, and video recordings of the operations allow the company to continuously improve the software. In July 2026, The New York Times revealed the existence of a facility in an undisclosed location in southern Germany-one that is unmarked, can be dismantled, and can be relocated within twenty-four hours in the event of a sabotage threat-with a production capacity of 1,000 HX-2s per month. A large portion of the workforce comes from the German automotive industry. The company's valuation has reached $18 billion; the federal government has approved a €220 million contract and has moved to acquire 50,000 drones for Ukraine.
Three elements of this case are of analytical significance. The first is the industrial model: production distributed across "resilience factories" allows, according to the company itself, nation-states to produce locally and maintain sovereignty over production and supply chains-an industrial response to the political problem of dependence. The second is the learning cycle: the software is updated based on operational data from the front lines, meaning that the European product improves as the war continues. The third is regulatory: Helsing states that it supplies only democratic governments, meaning it adopts a voluntary constraint where EU law has refrained from establishing a binding one. It is corporate self-regulation in place of public regulation, and the difference is not merely one of form.
The French position contains an internal tension that is worth clarifying. Paris led the coalition of member states that secured the exclusion of the military from the AI Act, defending national jurisdiction over defense matters; at the same time, it established channels of bilateral cooperation with the Ukrainian ecosystem, including the "Brave France" grant program-endowed with 20 million euros and signed by the Agence de l'innovation de défense with the Ukrainian cluster Brave1. There is genuine consistency between these two moves, but it must be properly framed: this is not a reluctance toward military AI, but rather a demand that it be governed in Paris rather than in Brussels. Strategic autonomy, as understood by France, is first and foremost autonomy from supranational regulation.
The Baltic and Nordic states have fulfilled a role that the major European powers have not assumed: that of producers of regulatory and strategic knowledge. The International Centre for Defence and Security in Tallinn has produced, through its series on the Russian war in Ukraine, some of the most precise analyses available in open sources, and did so by entrusting the drafting to a member of the Ukrainian Expert Committee. The final recommendations of that document-updating data protection policies unsuited to wartime, formulating a realistic vision regarding the legal limitation of human rights in conflict, and redefining the "human-in-the-loop" principle in light of future certification standards-constitute the most concrete regulatory agenda to emerge within the European context. The fact that it comes from an Estonian research institute rather than an EU institution speaks to the distribution of analytical capacity in Europe.
The result is a three-tiered architecture with weak connections between the levels. The Commission funds and coordinates without the ability to regulate; national governments regulate and procure without coordinating; companies produce, learn from the front lines, and self-regulate according to their own criteria. Each level acts rationally within the constraints it recognizes. The system as a whole has no single owner.
The issue of human oversight
All of the above issues converge on a single point. The "human-in-the-loop" principle is the cornerstone of every European position on this matter: the Parliament affirms it, the EDF's conditionality incorporates it, and Ukraine asserts it as its own doctrinal choice. However, we must examine what that principle actually means in operational conditions.
The Ukrainian formulation, reconstructed from the sources, describes a sequence in which the operator selects and confirms the target, after which the system executes the mission in just over thirty seconds. Human control is therefore real but situated at a specific point in the chain and subject to increasing time constraints. The ICDS document captures the problem when it points to the need to redefine the principle in light of future certification standards: if the principle must be redefined, it is because, in its current formulation, it does not hold up under the pressure of actual use.
The three safeguards identified in the specialized literature- the possibility of reviewing and reversing algorithmic outputs, clear lines of accountability, and the preservation of human judgment at decisive moments-are sound and, as things stand, have not been implemented in any European legal system with binding force. The first is technically problematic: the reversibility of a munition flying autonomously toward its target in an electronic warfare environment is not a computational operation; it is a physical window that closes. The second conflicts with the structure of the supply chain described above: when a system is designed in Germany, trained on data collected in Ukraine, integrated into a U.S. platform, and operated by a Ukrainian operator under national command, the attribution of responsibility is unambiguous not due to a lack of regulations but because of the system's configuration.
The third safeguard is the one worth emphasizing, because it conceals a conceptual substitution. The "centaur" doctrine -a combination of human intelligence and machine capabilities-is presented as the ethical solution, and it does indeed keep the human being in the loop. But it does so on the condition that the machine's speed does not exceed the threshold beyond which human approval becomes merely a formality. An operator who confirms targets at a continuous pace based on algorithmic recommendations does not exercise judgment: he or she ratifies. The shift from control to ratification requires no political decision, no regulatory change, no violation of principle; it occurs through increased performance. It is, in all likelihood, the way lethal autonomy will enter European arsenals-not through a choice against the principle, but through its silent erosion.
A Final Assessment
In light of the above, it is possible to formulate a balanced assessment of the European position, distinguishing between the degree of confidence in the evidence and the degree of probability attributed to these developments.
With high confidence in the evidence: the Union has deliberately refrained from regulating military AI, and this failure is attributable to the member states rather than to the institutions. European spending on AI-enabled capabilities is growing rapidly and is well documented. The European industry in this sector has reached a scale it did not possess in 2022, and it has achieved this thanks to access to a real operational theater.
With moderate confidence: the conditionality of funding is insufficient to produce the regulatory effects attributed to it, for the structural reason that European funding covers only a minority fraction of total spending.
As for scenarios, three appear plausible over a three- to five-year horizon. The gap between regulatory discourse and industrial practice is likely to widen, because none of the actors has an incentive to close it, and closing it would require a treaty amendment or a waiver of sovereign authority. It is possible, though not likely, that a crisis of attribution-an incident involving civilian casualties in which responsibility cannot be determined-could force emergency regulatory intervention; the key indicator to watch is the initiation of legal proceedings, whether national or international, concerning algorithmic uses of force. It is unlikely, within the timeframe under consideration, that the Union will acquire regulatory authority over military matters through ordinary legislative channels.
The most reliable indicator for distinguishing between these paths is not regulatory but industrial: the ratio of European spending on autonomous capabilities to spending on control, verification, and certification systems. As long as the latter remains an order of magnitude smaller than the former, the scenario described in this essay is bound to recur.
Europe Has Discovered War with AI
We have come to understand that the war in Ukraine is not the first war involving artificial intelligence. It is something analytically more interesting and politically more challenging; it is the context in which Europe has discovered that it wants algorithmic military capabilities before having decided under what conditions to deploy them.
The reversal compared to the model the Union had built in the civilian digital domain is stark and carries many implications. There, regulation preceded the market and defined its boundaries; here, the market precedes regulation, and regulation has been explicitly excluded by the very states that finance the market. This is not a matter of hypocrisy-which is a polemical category of little analytical value-but rather an institutional configuration that assigns regulation to a level lacking competence and capability to a level lacking coordination. Literally, the well-known European model of "success" (we're being ironic, of course).
The fundamental question remains, still unresolved and perhaps decisive for the Union's military future: Europe has built its regulatory identity in the technological domain on the idea that the human person must remain at the center of automated decision-making processes. This idea survives, in the military domain, as a formula. Its substance depends on a variable that no regulation controls: time. If the speed of systems continues to increase while the threshold for human reaction remains as it is, the "human-in-the-loop" principle will be preserved in letter but will dissolve in practice. Taking the ethics of military AI seriously in Europe would mean starting here, and it would mean admitting that the decisive question is not who decides, but whether there remains time to decide.
Politically speaking, as well as geopolitically, the EU has adopted a way of waging war against Russia that has transformed warfare and allowed for the experimentation with new hybrid approaches, but it has exposed the absurdity of the European system-capable of creating laws and regulations for just about anything, yet operationally ineffective and a failure. The problem is that the EU flaunts its regulatory capacity as if it were a victory, without realizing that the war it wanted and supported will not be won like in a video game. Nor will defeat be a video game.
According to some of the leading experts on strategy (we're being ironic again), it's likely that the bureaucratic apparatus in Brussels will be able to produce a regulation to even legally define its own defeat, but at least its conscience will be clear, and it will be able to say it has "won" its war.