elmerdata.ai blog

My blog

Blitzkrieg: b. 1940, d. 2026

Blitzkrieg, born in 1940 from the speed and shock of armored warfare, dead in 2026 as AI enabled drones gain the ability to navigate, recognize targets, and make increasingly consequential decisions without continuous human control.


Training a capable AI model can require millions of dollars of computing infrastructure. Putting the resulting intelligence inside a flying weapon may cost a few hundred. Ukrainian investigators who opened Russian drones downed over Zaporizhzhia this summer found Nvidia Jetson Orin modules inside them, small commercial computers that Nvidia sells to students, robotics developers and startups for machine vision work. Investigators say one of those drones chose its final target without a human operator and killed 3 civilians on July 6. The development worth attention is not that artificial intelligence has reached the battlefield, because it arrived years ago. It is how cheap the last mile of autonomy has become, and what that cheapness ends. Armored warfare has spent 86 years organized around a principle established in the spring of 1940, that the fastest decision on a battlefield belongs to the person closest to it, provided you hand him a cheap enough piece of electronics. The Zaporizhzhia wreckage is where that principle runs out.


Tiger I during Operation Citadel at the Battle of Kursk, June 1943

Friedrich Zschäckel, Tiger I during Operation Citadel at the Battle of Kursk, Soviet Union, June 1943. German Federal Archives, Bundesarchiv Bild 101III-Zschaeckel-206-35. Licensed under CC BY SA 3.0 DE.


What happened on July 6

Andrew Kramer reported in The New York Times on August 24 that Russia had tested self-targeting drones over Zaporizhzhia between May and July, and that Ukrainian investigators had recovered damaged but readable Nvidia hardware from the wreckage. The fatal case involved a small Molniya-type drone that approached a gas station. Human operators had directed it toward that general location. Once there, investigators concluded, the weapon selected the specific object it struck, most likely propane tanks, on the basis of training to recognize them. It failed to clear an apartment building, hit a wall and exploded. Tetiana Bubynets, a 19-year-old accounting student, Oleksiy Svirin, 41, and Roman Karpiy, 48, were killed.

Several pieces of evidence support the autonomy finding rather than any one of them alone. The drone carried no radio antennas, and it flew in a group of roughly 6, none of which transmitted. The recovered module was not encrypted, so investigators could read both the terrain imagery loaded for visual navigation and the object-detection code that defined what the system had been trained to look for. Vadym Kushnikov of the Kharkiv Aviation Institute described the result as a preprogrammed tool trained in virtual reality to track specific objects. Kateryna Bondar of the Center for Strategic and International Studies called the Nvidia module the best proof yet that Russia is experimenting with autonomous AI weapons, and told the Times that this appears to be the first documented case of civilian deaths caused by a Russian drone using fully autonomous targeting. That is a narrower claim than the one circulating in headlines, and the narrower claim is the one the evidence supports. A drone without an antenna could be following stored coordinates. What makes this case different is the combination: no operator link, onboard AI compute, stored terrain data, readable target-recognition code and behavior consistent with object selection.

The last mile moves

The phrase already had a meaning in drone warfare before this summer. Ukrainian and Russian units have both used computer vision for the final stretch of an attack, letting the aircraft hold its lock over the last few hundred yards when electronic warfare severs the link to the pilot. In that arrangement a person picks the target and the machine finishes the approach. What investigators describe in Zaporizhzhia moves the boundary. A person now picks the mission area, and the machine picks the object. That is a shift from guidance to selection, and it is the part of the story that matters more than the hardware.

Electronic warfare explains why the shift is attractive. Ukraine is one of the most heavily jammed airspaces on earth. A remotely piloted drone depends on a radio link that can be broken, and a satellite-guided weapon depends on a signal that can be jammed or spoofed. A system that navigates visually against stored imagery, recognizes categories of objects and decides locally offers no link to cut.

Russia does not need a machine that reasons like a person. It needs one that can answer a short list of narrow questions reliably. Where am I, where can I fly, what objects are visible, which of them match my training, and how do I reach one. Bondar's April analysis for CSIS captures the ambition in a phrase worth keeping: the result is not comprehensive autonomy but "functional independence at the tactical edge." That analysis reports the V2U system running a trained YOLOv5 network, recognizing vehicles, infrastructure and human activity by contrast, shape and motion rather than semantic classification. An ordinary open computer vision architecture, available to anyone for years, is enough.

Russia is also not alone. Former Ukrainian defense minister Mykhailo Fedorov has said Ukraine tested an entirely autonomous AI system in occupied Crimea over recent months against fuel storage and military equipment, with no reported civilian casualties, and the United States, China and Israel have all pursued increasing autonomy. Russia is the current case study because investigators recovered the hardware and tied it to a specific death toll.

Training is expensive, inference is cheap

The economics here follow from a distinction that AI governance discussions often collapse. Training asks how to build a model that can recognize a propane tank, and it can consume engineers, datasets, experiments and substantial compute. Inference asks what the camera is looking at right now, and it can run on a device that fits in your hand and draws a few tens of watts. Once the model exists, no deployed weapon repeats the training. Engineers copy the weights onto the next computer.

That is the property that makes this a software story wearing a hardware costume. Every airframe still needs a processor, camera, power supply and payload, and those cost real money. The intelligence does not. It replicates at close to zero marginal cost. The drone does not phone an Nvidia service or a Russian data center before deciding what it sees, because it carries the model with it. Intelligence has moved from the network to the weapon, and cutting the radio link does not stop a weapon that never had one.

The tank in the forest

The day after the drone investigation, the Times published the other end of the same equation. Ukraine's 33rd Separate Mechanized Brigade received Leopard tanks worth roughly $10 million each and now keeps them in Kharkiv Oblast forests under camouflage netting, gathering cobwebs. They come out mainly to tow damaged equipment, and mainly in bad weather, when wind and low cloud thin out the drones. Ukraine has reportedly lost up to 40 of its Western tanks. Oleksandr Syrskyi put it plainly: the army practically does not use armored vehicles, and the question now is how to neutralize the advantage drones have. Roughly half of one tank battalion has retrained as drone operators, and some new arrivals have never been inside a tank at all. A driver with the callsign Mekhan told the paper the era of conventional tanks is over. His commander thinks that if tanks have a future, it is unmanned.

Set the 2 reports side by side and the cost asymmetry stops being abstract. A machine costing a few hundred dollars, guided through its final seconds by a computer costing a few hundred more, can retire a $10 million vehicle to a treeline. That is not an incremental improvement in anti-armor weapons. It is a change in what a battlefield rewards, and the people it is happening to are rewriting their own doctrine at battalion level, ahead of the institutions that wrote the old one.

What 1940 actually proved

Cheap technology does not decide wars by itself, and the history usually invoked at this point says close to the opposite of what people think it says.

In May 1940 the German army attacked in the west with 2,582 tanks. The Allies had 4,204 between them, including more than 3,200 French tanks on the northeastern front alone. The German fleet was also the worse one. Its 2 most numerous vehicles were the Panzer I, armed with machine guns, and the Panzer II, with a 20mm gun. Only 629 of those 2,582 were Panzer IIIs or IVs. France fielded the Somua S35, whose 47mm gun could defeat any German tank at 1,000 meters, and the heavier Char B1. On paper the campaign should have gone the other way. It was over in 6 weeks.

What Germany had was not better armor but a different arrangement of ordinary parts. Tanks were concentrated in panzer divisions with their own infantry, artillery, anti-tank and signals units and dedicated air support, rather than spread along a defensive line in support of foot soldiers. And the whole structure was built around radio. Guderian's design principle was a set in every tank. A French tank platoon typically had 1 radio, in the commander's vehicle, and 4 machines with none, and in tanks like the S35 that commander was also aiming and loading his own gun. When a German unit met something unexpected, the information moved at the speed of a voice. When a French unit did, it moved at the speed of a runner. Karl-Heinz Frieser's account goes further and argues the breakthrough outran its own plan, driven by subordinate commanders exploiting an opening faster than either high command could follow. Blitzkrieg was less a doctrine executed than a doctrine discovered.

Carry the shape of that forward. The decisive edge in 1940 was not the armored vehicle, which everyone had, and it was not a better armored vehicle, which France had. It was a cheap communications device distributed to every unit, combined with an organizational decision to let the people holding it act on what they heard.

Which is what makes the present moment a conclusion rather than a repetition. In 1940 a radio went into every vehicle so the machine at the front could be told things faster. In 2026 a model goes into every vehicle so the machine at the front does not have to be told at all. Both are commodity electronics pushed to the edge and both move initiative downward, but they do not end in the same place. In 1940 the bottom of the chain was a crew commander with a headset, and the technology made his judgment faster. What Ukrainian investigators pulled out of the wreckage at Zaporizhzhia has nobody in it at all.

Be precise about what that kills, because the tank itself may well survive. Active protection systems, cope cages, unmanned turrets and the M1E3 program all suggest armor adapts, and the analysts insisting the death of the tank has been exaggerated have the better historical record on their side. What does not adapt is the arrangement that made armor decisive in the first place. Blitzkrieg was never a machine. It was mission command with a radio: devolved initiative, exercised by a human at the edge, at the speed his equipment allowed. Push the equipment one generation further and the human at the edge becomes the slow part, and then becomes optional. That is the thing with a death date on it.

A component that looks like nothing in particular

Jared Diamond's Guns, Germs, and Steel is remembered for geography, but the chapter that matters here is "Necessity's Mother," where he inverts the cliché and argues that invention is often the mother of necessity rather than the other way around. Things get built by people solving some other problem, or no stated problem at all, and the uses arrive afterward. The internal combustion engine and the transistor were not built to a military requirement, and both were in uniform within a generation. War is where repurposing happens fastest, because the motivation to find a new use for an existing thing has rarely been stronger than under fire. Nobody had to invent a computer for autonomous weapons. Somebody had to notice that one was already on sale.

That is why making Nvidia the story would be a mistake. Nvidia says Jetson modules are consumer-grade products sold to students, developers and startups for beneficial applications, that they are not sold in Russia, and that resellers put used units into circulation the company cannot track. If a US manufacturer were knowingly supplying autonomous weapons to Moscow, the policy problem would be comparatively easy to state and to solve. The actual problem is harder, and the CSIS component analysis shows its shape. Across 705 AI-relevant components identified in Russian unmanned systems, US-headquartered firms account for more than half, including roughly 57% of processors, 69% of memory and 38% of sensors. That does not mean American companies sold weapons technology to Russia. It means the commercial semiconductor supply chain has become part of the military AI supply chain.

The controls are not doing nothing. The Bureau of Industry and Security, working with the EU, Japan and the United Kingdom, maintains a Common High Priority Items list of 50 tariff codes that Russia is known to seek, and the guidance notes plainly that items in its top 2 tiers have been found in Russian missiles and drones on the battlefield in Ukraine. The list exists because ordinary electronics keep arriving anyway. Export controls were built for objects with a particular profile: specialized, expensive, made by few manufacturers, wanted by few civilian buyers, hard to move quietly. Jetson-class computers have almost the opposite profile. They are cheap, commercial, in enormous legitimate demand, small enough to post, and useful in a factory, a tractor, a laboratory or a delivery robot. A customs officer cannot infer intent from the part. The V2U reportedly pairs an Nvidia module with a Chinese Leetop carrier board, which is the whole difficulty in one sentence.

"Dual use" is not quite the right label. The better word is composability. A commercial processor, a camera, storage, navigation sensors, an open-source machine learning framework, a trained network, an airframe and an explosive charge are individually mundane, and the weapon exists only in the assembly. Governance regimes designed to control finished objects struggle when the dangerous capability appears only after ordinary parts are combined, and hardware controls cannot reach the half of the problem that is software. Russia has concentrated on applied AI rather than frontier model development precisely because the models and frameworks it needs are already public, and stopping every copy of an algorithm is harder than stopping every processor.

What governance loses when the model leaves the cloud

Nearly every AI governance framework in enterprise use assumes someone still operates the service. Administrators can revoke credentials, inspect logs, restrict an API, roll back a version or shut the thing off, and those levers exist only because the intelligence lives somewhere the vendor controls. Move a trained model onto a physical device in someone else's possession and the levers go with it. There is no account to disable, no traffic to monitor, no central log, no remote stop, and often no idea where the computer went or what it now runs.

I keep arriving at this seam from different directions. I have argued that context engineering is governance at inference time, that the SEC's silence on agentic trading leaves deployment responsibility unassigned, and that governance arrived too late for agentic AI. Edge autonomy is the physical version of the same gap. Frontier-model policy concentrates on training, where capability is concentrated and a small number of firms can be regulated. Deployment is where capability gets used, and inference is proliferating faster than anyone is governing it. The drone is the most disturbing illustration, but the pattern runs through vehicles, medical devices, industrial equipment and surveillance systems that increasingly run their models locally.

Nvidia's announcement on August 25 illustrates the direction without implying any connection to the Russian use of older hardware. The Jetson Orin Nano 2 is promoted for robots, delivery drones, inspection drones and embedded vision, and Nvidia says it delivers up to 78 trillion operations per second, roughly twice the inference performance of its predecessor, or comparable performance at about 40% less power. The module is expected in the first half of 2027 and no price has been announced. The trajectory is unmistakable regardless: more inference, less electricity, smaller packages, lower cost per unit of capability. Whatever governance manages to do about today's part number, tomorrow's will be more capable and more ordinary.

Where human judgment has to stay

There is one historical case people reach for when they want to believe a dangerous technology can be put back in the box. Japan acquired firearms from Portuguese traders in 1543, manufactured them enthusiastically enough to hold more and better guns than any country in the world by 1600, and then, under a samurai class for whom swords were both status markers and works of art, let them dwindle until Commodore Perry's fleet arrived in 1853. Diamond tells that story as his example of a society reversing course on a technology.

It is also, as Japanese historians have argued for decades, mostly a myth. Tamara Enomoto traced the popular version to Noel Perrin's 1979 book and found the record contradicts it. Villages held firearms in quantity for hunting and pest control. The Kumamoto domain recorded 1,630 guns in peasant hands in 1634 and 2,173 by 1641, often more than the warrior class held in the same domain. The famous 1588 ordinance was aimed at sword-carrying rather than gun ownership. What Tokugawa Japan actually operated was not abolition but registration, background checks and supervised storage, administered locally. The correction is more useful than the myth. The one case cited as proof that a weapon can be renounced turns out to be a case of governing possession and accountability rather than eliminating the object.

That is roughly the only option now, and it is what the diplomacy is groping toward. On August 25, UN Secretary-General António Guterres and ICRC President Mirjana Spoljaric renewed their call for binding international rules on autonomous weapon systems, with Guterres warning that "we are now dangerously close to crossing a moral red line: the autonomous targeting of humans by machines." They want prohibitions on unpredictable systems and on anti-personnel autonomous weapons, and they name the CCW Review Conference in November as the clearest available path to negotiations. The Group of Governmental Experts on lethal autonomous weapons reconvenes in Geneva on August 31. Existing humanitarian law already applies to these systems; what the appeal seeks is something more specific, and it is not settled law yet.

The hard part is not that machines make mistakes, because so do frightened and exhausted people, and some experts argue that a weapon able to perceive and evaluate before striking may prove safer than an unguided bomb or an artillery shell. That argument deserves to be taken seriously, because the alternative to autonomous targeting is not perfect human judgment. The hard part is that recognition and legality are different tasks. A model can become excellent at identifying a propane tank and still have nothing to say about whether striking it is lawful. Distinction, proportionality and precaution are contextual judgments, and the same tank can be civilian infrastructure, part of a military facility, empty, full, temporarily repurposed, or standing beside an apartment building where people are sheltering. Computer vision answers a classification question. The law asks a normative one.

None of this makes the chip responsible. People decided to invade, chose the operational area, built the drone, trained the model, wrote the list of objects worth striking and launched the weapon. Autonomy operated inside boundaries that humans set. What changed is where human control stops, and that is the question Geneva actually has to answer: which decisions may software assist, which may it execute, and which must remain with a person. It is the Tokugawa question in modern dress. Not whether the object may exist, but who must answer for its use.

The uncomfortable part

The most striking fact about the Zaporizhzhia case is not that Russia obtained an exotic Nvidia AI chip. It is that it did not need one. Ordinary commercial technology now supplies enough local compute to perform narrow but militarily consequential tasks for a few hundred dollars, and better models on better edge hardware will keep pushing that number down relative to capability.

The strategic consequence runs past target recognition accuracy. A drone pilot is a scarce resource who must be recruited, trained, connected and protected, and who can fly one aircraft at a time. Autonomy changes the ratio between human labor and deployed weapons, so the limiting question stops being how many pilots a force can field and becomes how many platforms it can build. No swarm intelligence is required for that, only cheap independence. Whether any of it becomes a coherent way of fighting is a separate question, and 1940 is the reminder that the answer depends on organizations rather than components. France had the better tanks. Germany had the radios and the willingness to reorganize around them.

Traditional arms control assumed scarcity. Fissile material is hard to get, lithography tools have few makers, frontier training runs require enormous compute. Edge inference breaks the assumption at the point where it matters, because training may stay concentrated when deployment does not. We spent several years asking who would build the largest models. Autonomous warfare forces a different question: what happens when enough intelligence becomes cheap enough to put anywhere?


Further Reading

From this blog

Sources


AI Assistance Statement ▾
Preparation of this blog entry included drafting assistance from ChatGPT using a GPT-5 series reasoning model. The tool was used to help organize ideas, propose structure, refine language, and accelerate revision. It was also used to assist in identifying image sources and verifying that selected images appear to be released for reuse (for example through public domain or Creative Commons licensing). The author selected the topic, determined the argument, reviewed and edited the text, confirmed image licensing, and takes full responsibility for the final published content.

#AIData #History #Observations