Illustration: Louiza Karageorgiou for GIJN
Guide to Investigating Tech and AI in Modern Warfare
When historians look back on the wars of the 2020s, they may be struck by two things.
The first is that vast wells of content that traditionally helped such historians report on wars are completely missing. The modern equivalent of the diaries of the Great War? WhatsApp messages long deleted. The comparable typed-up Situation Reports — if they survived being destroyed — once found in the Vietnam War? Vanished on corroded servers. Immense tracts of digital data might be lost to time.
The second insight might be a struggle to locate the frontline of the fighting. Was it where civilians were most harmed? Was it the headquarters of a drone squadron? Was it on the servers of some tech giant? The physical geography of modern armed conflict, once defined by that thin red line of battle, has extended and extended, so that the operational frontline is harder and harder to place. A complex map of the digital battlefield would emerge, that would include satellite constellations, cloud contracts, server archives, and arms and tech supply chains.
The true nature of modern war is not found in the images that we see on our smartphone screens: the shattered apartment block, the mass grave, the cries of mothers at a black-bowed funeral procession. As the author CS Lewis once noted, these are its final results. The violence begins elsewhere. It is conceived, authorized, financed, coded, and contracted in conference rooms, data centers, and technology offices. It advances through procurement frameworks, cloud-service agreements, venture-capital investments and software updates. Decisions to purchase such technology are moved, seconded, approved and minuted long before a missile strikes its target.
The reporter’s task, therefore, is not simply to document the result of violence, but to reconstruct the process that produced it. The battlefield today extends far beyond the shell-holes of impact. It runs through bureaucracies, corporations, tech-hubs and financial institutions. The explosion might be the final expression of a line of decisions, relationships and incentives that began long before any weapon was launched. To understand modern conflict — more than ever — has to be to trace that chain backwards, from harm to system, from incident to infrastructure, from death to the details of a technological machinery that made it possible.
It is this labor that forms the main focus of this guide: how to investigate a contemporary conflict that increasingly operates through a blurred space between military and civilian systems, where cloud platforms, surveillance networks, AI models and commercial infrastructure have become embedded within warfare itself. It means tracing the chain from battlefield harm back through the systems that enabled it.
An Amnesty International investigation into Sudan, for example, used analysis of bomb fragments to identify Chinese-made guided munitions that it concluded had almost certainly been re-exported by the United Arab Emirates to the Rapid Support Forces in breach of the UN arms embargo. Equally, investigations into the war in Gaza have examined how commercial AI platforms and data services supplied by companies such as Palantir have become embedded within military targeting systems, raising profound questions about corporate responsibility for civilian harm.
The challenge, of course, is for journalists to be able to track lines of responsibility that are fragmented across states, companies, supply chains, and technical architectures in ways that make accountability far harder to establish.
Needless to say, the urgency of doing this is acute, because the pace of digital development has been startling. By early 2025, the Royal United Services Institute, a London military think tank, estimated that drones accounted for 60-70% of damaged or destroyed Russian military equipment in Ukraine. It was a figure that would have seemed fantastical a decade ago. By 2026, the military-tech nexus had become so distinct that, in the US-Iran war, Iran deliberately targeted the global delivery service Amazon’s data centers in the UAE and Bahrain.
Digital is no longer seen as assistance to fighting; it is deemed integral to its waging.
As we see a shift towards the digital battlefield, so too have human rights concerns risen. The International Committee of the Red Cross (ICRC) has urged states to keep AI in conflict firmly subordinate to human judgment. It’s a battle towards moderation that, to be frank, is not really working. Goodwill United Nations talks toward a binding instrument on lethal autonomous weapons have so far stalled. And it’s not controversial to say that international regulation is lagging behind the realities of modern conflict.
It is into this gap that journalism must now step.
So, the question for reporters is no longer whether militaries are using AI systems. It is, rather, in what ways have these systems become part of a killing machine? Who sells them? What profits are made from them? Where does the targeting data come from? How much control do humans have in practice? What happens when systems of civilian protection fail (or don’t exist in the first place)?

An Amnesty International investigation into Sudan used analysis of bomb fragments to identify Chinese-made guided munitions that it concluded had almost certainly been re-exported by the United Arab Emirates to the Rapid Support Forces in breach of the UN arms embargo. Image: Screenshot, Amnesty International
From Military-Industrial to Military-Tech Complex
To arrive at a deeper understanding of what the new digital battlefield looks like, perhaps we first have to accept that the phrase “the military-industrial complex” is some 60 years old and a bit threadbare. Contemporary warfare is organized not just around a clutch of arms manufacturers; instead, a wider “military-tech” complex has grown where cloud infrastructure, AI models, analytics, sensors and communication systems enable war to be planned, fought and — even — narrated.
So, in the West, this system includes the likes of Microsoft, Amazon, Google, Palantir Technologies, Anduril Industries, OpenAI, and Anthropic (despite controversies involving the last). China has developed its own “military-civil fusion,” with firms like Huawei, Tencent, and SenseTime being deeply embedded in their military might. While Russia relies on a more state-directed nexus centered on Rostec, Yandex, and a host of cyber, drone, and dual-use suppliers that operate within and beyond the sanctions regimes facing the Kremlin.
Combined, these firms have evolved into a highly profitable tech-arms race, where artificial intelligence, autonomous systems, social media platforms and quantum science are reshaping remote warfare from the inside, as well as changing how it is viewed from the outside.
The money involved is eye-watering. In its 2027 budget, the Pentagon requested more than US$54 billion to fund the Defense Autonomous Warfare Group, including “autonomous and remotely operated systems across air, land, and above and below the sea.” This was a 24,000% increase on 2025. In May 2026, it was reported that Helsing, the German defense technology group was on track to raise funding of about US$18 billion, making it one of Europe’s most valuable start-ups.
The rise of these digital behemoths is causing a power shift. Yes, states still command, but capability (surveillance, communication, automated decisions) are increasingly exercised by firms whose customers and staff are still largely civilian, and such civilian platforms are being weaponized. An Associated Press investigation into commercial AI use in Gaza and Lebanon documented a wartime surge in the use of off-the-shelf models for transcription, translation, and search across intelligence stores. The research claims that AI models (in this case, from Microsoft) primarily made for civilian use were allegedly extensively used for military purposes. Microsoft didn’t respond to the AP journalists for this story.

An Associated Press investigation into commercial AI use by Israel in Gaza and Lebanon documented a wartime surge in the use of off-the-shelf models for transcription, translation, and search across intelligence stores. The research claims that AI models (in this case, from Microsoft) primarily made for civilian use were allegedly extensively used for military purposes. Image: Screenshot, Associated Press
A different joint investigation by the Guardian, +972 Magazine, and Local Call also reported that audio files of millions of Palestinian phone calls had been stored on a Microsoft/Azure platform and from there had been used to plan airstrikes and arrests. Microsoft has since said it has blocked certain Israeli uses of its technology, but the harm has been done, and the precedent struck.
It’s not some murky, unethical, unheard-of company crossing a moral line in assisting the killings of civilians. Rather, global commercial systems are part of the operational IT infrastructure that enables warfare. The boundary between civilian tech product and military application is thinner than it has ever been.
The idea of dual-use technology makes the picture even murkier. A dual-use item is defined by the US Bureau of Industry and Security as one that has civil application alongside military or weapons-related use. So, for instance, high-performance integrated circuits are dual-use items because they power civilian data centers while also enabling advanced military computing systems. The European Commission’s guidance on cybersurveillance exports warns that items with legitimate civilian functions (for instance, law-enforcement analytics or network monitoring) can be repurposed and, as such, “pose a risk for internal repression or serious violations of human rights and international humanitarian law in the importing country.”
Some products are dual-use incidentally, but others are deliberately marketed across both spheres because civilian revenue subsidizes defense research and development (R&D) and softens reputational risk. Tech Policy Press, for instance, reports that some of the biggest AI companies are even using humanitarian deployments to leverage and learn from data, surveillance, and IT systems that can also be used in military targeting and intelligence ops.
Two Chains, One Story
So where to begin investigating? The most useful starting point is to look into two separate things.
First, we have the chain of command: who decided that an operation should go ahead? It is a command structure that runs vertically through military officers, lawyers, brigade commanders, and political ministers. At its heart lies, or should lie, rules of engagement, civilian protection mechanisms, and the issue of proportionality in war (for more on legal proportionality and command structures, read GIJN’s War Crimes Reporting Guide). This chain of command, in the end, authorizes the bombs and bullets that lie at the heart of most investigative war reporting. And this chain of command, in theory, should be relatively impervious to the new technology forming around it. But it would be naïve to think that enhanced technologies do not shape kill orders and battlefield tactics. Proving this, however, is a challenge.
Second, there is the chain of systems: journalists should investigate what linkages and digital connections made these targeting decisions possible. This system runs through cloud vendors, telecoms carriers, platform operators, subcontractors, university and corporate research laboratories, data brokers, exporters, logistics firms, and, perhaps most critically, the investors, venture funds, sovereign wealth vehicles, and insurers whose capital made the capability viable in the first place. This chain is far more opaque.
The distinction becomes clearer in practice. Investigations into Israeli military operations in Gaza, for example, have examined both chains simultaneously. The chain of command concerns who authorized particular strikes, how proportionality assessments were conducted and which officers approved targeting decisions. The chain of systems asks a different set of questions: which cloud platforms stored the intelligence, which AI systems helped process it, which companies supplied the software, where the infrastructure was hosted, and who financed or maintained it. Together, these two chains reveal not only how an attack was authorized but also how it became technically possible. Modern investigations increasingly need to examine both.
Pillars of Technological Warfare
To penetrate this opacity, modern conflict can usefully be broken into five pillars of the chain of systems. These are not in chronological order, but they are all interconnected.
- Weapons and components
- Infrastructure
- Information
- Surveillance
- Automated decision support
As it stands: weapons depend on infrastructure; infrastructure enables information flows; information systems feed surveillance; surveillance shapes targeting; and automated decision systems accelerate how weapons are deployed.
Any deep-dive report into the chain of systems will have to look at several if not all of them.
Weapons and Components
Hardware still matters, and in some ways it is easier to investigate than software. The closer to the more physical hardware, the more obvious the evidence.
Wreckage, serial numbers, customs codes, tenders, component markings, training artefacts, and manufacturer literature all leave trails that can lead you into a deeper insight into the digital hand of warfare at play. As such, collect or photograph and catalog every serial number, batch code, customs identifier, manufacturer logo, and technical marking that you can find of battlefield remnants at any point of concern (i.e. a bombed school or hospital). These can sometimes be matched to procurement records, customs declarations, shipping manifests, patents, and export licenses.

A US-manufactured AGM-114 Hellfire missile fragment showing the marking plate and serial number at a crater site in Gaza. Image: Shutterstock / Anas Mohammed
Ask five questions of every component: who made it, who sold it, who shipped it, who paid for it, and who authorized its export?
Search the SIPRI Arms Transfers Database for information on major weapons transfers, the SIPRI Arms Industry Database for company information, and the United Nations Comtrade database for international trade records. Of course, in lots of wars, there won’t be such traceable systems, but it’s a start.
Government export-control portals, including the UK’s Strategic Export Controls database, the European Union’s dual-use and sanctions registers, and the United States’ export-control databases, can reveal licensing decisions and declared end users. Procurement platforms such as TED (EU Tenders Electronic Daily), national contract registers, and defense acquisition portals can reveal purchasing relationships. Corporate records available through OpenCorporates, UK Companies House, the US Securities and Exchange Commission’s EDGAR database, and others can identify ownership structures, subsidiaries, and financial flows.
Shipping and supply chain databases such as ImportYeti, Panjiva, ImportGenius, and commercial maritime tracking platforms might throw you a lead in terms of naming digital suppliers, intermediaries, and software support systems.
If stuck, try OCCRP’s Aleph database, national court filings, sanctions lists, and even lobbying disclosures. They can sometimes give you additional leads.
Meanwhile, manufacturers themselves are often among the best sources. Defence companies routinely publish product brochures, investor presentations, annual reports, exhibition catalogues, technical specifications, and press releases that identify where systems have been tested, demonstrated, or sold.
If you can, go to a weapons fair, such as the Paris Air Show, DSEI, and Farnborough International Airshow, and take a big bag. There you can get access to catalogs, promotional materials, and even contract announcements that might be difficult, if not impossible, to find elsewhere or online. Also, if you can’t locate what you are looking for, remember that archive services such as the Internet Archive’s Wayback Machine can recover deleted marketing claims and product information.
An example of a story that took a photograph from a missile strike and led it back to its origin is this 2026 Action on Armed Violence investigation, by this author, where the Tomahawk missile that attacked the girls’ school in Minab, Iran, consisted of digital components that could be traced back to UK-based manufacturers. For more on arms trade, read this chapter in GIJN’s War Crimes guide.
Infrastructure
Once you have considered the front-end of harm, think of the digital infrastructure that keeps the cogs of war turning. So, consider the cloud services, telecoms, satellite internet, data centers, and undersea cables that are all operational assets in any war.
They are also — increasingly — the targets of war. Attacks on systems of communication are increasing, for instance. Indeed Access Now’s #KeepItOn coalition sees internet shutdowns as causing specific human-rights harm that enable “covering up atrocities during conflict, quelling protests or gagging citizens during important national events like elections.” Its Shutdown Tracker Optimization Project has documented hundreds of shutdowns globally, many coinciding with grave abuses.
Increasingly, complicity in digital infrastructure shutdowns can be found in current wars. This 2025 Reuters investigation found that Elon Musk personally ordered SpaceX engineers to shut down Starlink coverage during Ukraine’s 2022 Kherson counteroffensive, causing battlefield communications failures that disrupted Ukrainian operations and triggered panic. Musk didn’t respond to requests from Reuters for comments, though he wrote on X that “we would never do such a thing.” In Gaza and beyond, as reported by Al Jazeera in 2023, civilian digital infrastructure was also deliberately targeted by Israeli forces, attacking telecommunication towers of Palestinian companies like Jawwal and Paltel. Additional examples include the cable cut in the Red Sea and the Russian cyberattack on Ukraine’s largest telecom operator and its Ministry of Justice.
Another critical element of digital infrastructure is data. As the Center for Strategic and International Studies has it: Data Is Now the Front Line of Warfare. This report shows how data centers are new targets in warfare, sometimes with strange but meaningful consequences. As the Jerusalem Post reported in 2026, the strike hitting the data center of the Iranian bank disrupted the payment of salaries to the Iranian military.
Again ask questions. Which state agency requested it? Was the law broken? What was the real price paid by civilians (from disrupted medical services, to interrupted emergency communications, to blocked humanitarian coordination, to families unable to locate displaced relatives)? Who owns the data pipes, satellites, or infrastructure elements? And which pieces of private infrastructure have become militarily indispensable?
Internet shutdowns can be tracked through Access Now’s Shutdown Tracker Optimization Project (STOP), the Open Observatory of Network Interference (OONI), Cloudflare Radar, and NetBlocks. Ownership records for telecoms providers, internet service providers and data-centre operators can often be found through OpenCorporates, Companies House, SEC filings, and national telecommunications regulators.
Submarine cable ownership and routes can be examined through TeleGeography’s Submarine Cable Map, while satellite infrastructure can be tracked through filings with the International Telecommunication Union (ITU), national spectrum regulators and company disclosures. Technical outages and cyber incidents are often documented by organizations such as the CyberPeace Institute and Citizen Lab.
Perhaps take time to read Reuters’ investigation US and China Wage War Beneath the Waves, which traced how governments and technology companies compete for control of undersea internet cables. What you are really reading is how ostensibly private infrastructure has become a strategic asset at the heart of modern geopolitical conflict. And, if you are interested in the intersection of conflict and space, then in his book “The Future of Geography,” Tim Marshall explores the emerging field of “astropolitics,” arguing that humanity has entered a second space race in which control of orbital space, lunar territory, and extraterrestrial resources will become increasingly important determinants of geopolitical power. It’s a good read.
And if it sounds like science fiction, secret Russian and Chinese military documents exposed by The Insider revealed that Moscow and Beijing have developed a far deeper defense partnership than previously known, including plans to disrupt or destroy Starlink, jointly develop advanced air and missile defence systems, and exchange Russian battlefield experience in Ukraine for Chinese technology and manufacturing capacity. Star Wars may be closer than we think.

This Reuters’ investigation traced how the US and Chinese governments and technology companies compete for control of undersea internet cables. Image: Screenshot, Reuters
Information: the Participatory Battlespace
As Francis Bacon first conceived more than four centuries ago, “knowledge is power,” a maxim that has become ever relevant in an age where information itself is a strategic asset. War is being witnessed, captured, relayed, and consumed in real time in ways that mankind has never seen before.
The growth of social media is at the center of this. Scholars writing on the military-social media complex describe a new ecology where “the distinctions of combatant, civilian, and informational warrior implode.” Where opposing groups upload material minute by minute, platforms shape what is amplified, demoted, or removed, and which accounts are amplified or suspended.
The UK-based charity Business and Human Rights Centre’s 2023 report revealed how Israel pushed dozens of ads on YouTube and X with brutal imagery to win support for their military response to the Hamas attacks in October 2023. The platforms’ “set standard” of what can be posted on their streams, in this case, helped Israel’s social media campaign. Therefore, platforms are no longer passive carriers of wartime information. They shape what audiences see, what militaries can deny, and which narratives gain ground and — by not being suspended — legitimacy.
In addition, and more obliquely, it’s worth noting that AI services used by platforms like Youtube or Facebook to protect users from violent content can also lead to the destruction of evidence of war crimes. This has been the case in Ukraine, as the BBC reported in June 2023, where videos of human rights violations were taken down without being archived, when they could have been useful in war crimes prosecutions.
To investigate this information battlespace, follow the data (which is another word for money, really). Start with platform transparency databases such as Meta Ad Library, Google Ads Transparency Center and TikTok Creative Center. These would help you, if you get a break, to identify who is paying to promote wartime narratives and which audiences are being targeted.
Then you can use OsoMeNet and Gephi that offer ways to help you map how stories spread through networks of influencers, state media, or anonymous accounts. For removed content, the archives of Mnemonic, Bellingcat, and the Internet Archive Wayback Machine, might help you find or preserve material that may later disappear. Scrutinize platform transparency reports from Meta Transparency Center, Google Transparency Report, and X Transparency Center to determine whether governments are requesting content removals or account restrictions during conflicts (though perhaps it is telling that X is so committed to the open exchange of information that their last Transparency Center report was in 2024).
For issues such as AI manipulation, comparing deleted videos with copies and other ways to look at AI’s impact, head to organizations such as Witness, the Human Rights Center Investigations Lab at the University of California, Berkeley, and Syrian Archive, which all have various digital archives. If you have 90 seconds, this is how the BBC tells if a video is AI or not (it’s looking for visual inconsistencies, searching for physical and digital watermarks, finding the source, or speaking to experts if you don’t have 90 seconds).
Surveillance
This pillar is where, you could argue, the waging of war and where ordinary state monitoring and intelligence gathering become hardest to separate and to investigate. So things like intercepted calls, biometrics, facial recognition, and even population registries might be presented as legitimate and reasonably security systems. In practice, they can also be integral to targeting, detention, or other forms of coercive control (they can also be used to identify the dead). The ICRC has warned that armed forces are increasingly leveraging biometrics and that facial recognition is moving closer to battlefield targeting.
You might also find that systems used in one country and implicated in harm are also used and justified in another country — such as this Al Jazeera investigation into how the UK government is expanding police use of AI facial recognition technology supplied via a subcontractor, Israeli firm Corsight AI, whose software has been used by Israeli forces in Gaza, prompting criticism from human rights groups over privacy concerns, civil liberties, and the UK’s partnership with a company linked to alleged abuses in the occupied Palestinian territories. Al Jazeera journalists didn’t get any response from the Israeli firm.
Facial recognition systems work by detecting faces in images or video, extracting biometric data to create a unique mathematical “faceprint,” and comparing it against databases, including through data-sharing systems that allow agencies to check and request matches across different databases. Imagine a hovering killer drone equipped with such a system — preloaded with a host of kill lists — monitoring the ground beneath, searching for a match.
Such intelligence can be easily transformed from legitimacy to harm. A biometric system that was explicitly built for border control could easily be redeployed for a military occupation or towards discriminatory surveillance; a predictive-policing platform refined in domestic law enforcement can be exported to another state where it is used to suppress freedoms of speech.
One example, reported by The Times (UK) in 2021, was how the Chinese border surveillance data firm Nuctech secured more than £12 million (US$16.3 million) in UK contracts for prison and border-scanning equipment. This same product was used for stringent border controls in Nicaragua, flagging names on flight manifests and banning investigative journalists (namely, reader, this author).
The same infrastructures, then, used by policing, migration control, occupation and war, often have the same vendors, the same engineers and the same data prejudices embedded within them. The LA Times reports on a targeting system that fuses all kinds of data, including Wi-Fi, traffic cameras, government databases, and social media, to track Hezbollah members. This system contains computing powers developed by Amazon and Microsoft, and retrieved data from commercial platforms.
Tracing the money, again, is often a way into discovering who is using what. The investigation into Pegasus, the sophisticated surveillance platform developed by Israel’s NSO Group, illustrates how different investigative techniques can reinforce one another. The wider Pegasus Project, led by Forbidden Stories with Amnesty International’s Security Lab and media partners, first established through forensic analysis that Pegasus had been used to infect the phones of journalists, activists and politicians across multiple countries. Building on that work, an OCCRP investigation matched import records and bills of lading to hardware specifications consistent with Pegasus deployments. Reporters may not always be able to prove the operation of proprietary software directly, but procurement records, customs paperwork, contracts, and hardware shipments can collectively provide compelling evidence that surveillance capability has been acquired.

This OCCRP investigation matched import records and bills of lading to hardware specifications consistent with Pegasus deployments. Image: Screenshot, OCCRP
So, to investigate surveillance systems in conflict, as with the issues above, it is best to start with the procurement trail. Search procurement portals such as TED (Tenders Electronic Daily), UK Contracts Finder, USASpending, and customs databases such as ImportGenius or Panjiva to identify who bought surveillance technology, when it was delivered and which companies supplied it. Perhaps for facial-recognition and biometric systems, examine technical patents through Google Patents or look at evidence gathered by groups such as Amnesty International’s Security Lab.
Ask who built the database? Where is the data stored? Which agencies can access it? Has the system ever crossed from identification into targeting? Look for any technical manuals, patent applications, export licences, and investor engagement that might set down a digital breadcrumb trail that leads to harm. In short, look for the gaps that let the light in.
Additionally, it’s worth being acquainted with the Wassenaar Arrangement, the European Commission’s cybersurveillance guidance, and the US Export Administration Regulations. These explain what is formally treated as dual-use, and where exporters are meant to consider repression and humanitarian-law violations.
Automated Decisions
As noted, automated decision systems have been increasingly used in warfare in the past decade. These are often legitimized by the argument that they improve target precision and make war less lethal for civilians. So investigate: is this the case? Also ask: what does the software actually do to the pace of war? Does it extend the palatable thresholds of violence? What does it do to our own sense of the human, and to the moral responsibility of those making life-and-death decisions?
Recent reporting offers useful starting points. Investigations by +972 Magazine and Local Call into the Israeli military’s reported use of the AI systems Lavender and The Gospel suggested that machine-assisted targeting dramatically accelerated strike decisions, while raising questions about the extent of meaningful human oversight. Israel has rejected claims that AI autonomously selected targets, stating that such systems merely assist human analysts. Likewise, the US military’s Project Maven has become a focal point in debates over automation in warfare, using machine learning to analyse drone and satellite imagery and compress the time between detection and targeting, prompting wider questions about accountability as the kill chain becomes ever faster.
Researchers at Utrecht University have also argued that such systems risk compressing the time available for proportionality assessments and legal scrutiny within military command structures. It’s worth noting that technological warfare disperses responsibility while preserving lethality. As Lauren Gould of Utrecht University has argued, responsibility blurs: “The commercial companies developing these systems argue they have no control over how their technology is used, and governments often deny using them altogether.” Military officers point to procedures, companies deny operational control, governments deny their use (under the guise of secrecy), and you are reassured that a human being remains formally somewhere in the loop, but you are never given a name or a rank of the person in the kill chain. Tellingly, perhaps, some Western militaries lack formal civilian casualty units.
The task for journalists is therefore not simply to describe new military technologies, but to investigate the gap between their promised effects and their real-world consequences. As GIJN’s War Crimes Reporting Guide makes clear, scrutiny of civilian harm, command responsibility, and targeting practices remains essential regardless of how advanced the technology appears.

The Guardian has reported that Anthropic’s AI tool Claude was used by the US military in a barrage of strikes against Iran that “shortens the kill chain.” Image: Screenshot, the Guardian
The consequences of this shift are already becoming visible. The Guardian has also reported that Anthropic’s Claude was used by the US military in a barrage of strikes that “shortens the kill chain” (the process from target identification through legal approval to launch). As Craig Jones and Helen M. Kinsella of Newcastle University have put it: “Two decades ago, it was easy to dismiss as hyperbole the idea that the coming age of cyberwarfare might bring about ‘bombing at the speed of thought,’ a phrase coined by US historian Nick Cullather in 2003. Yet with the advent of AI warfare, the unthinkable has become almost antiquated.”
And this acceleration will keep going. New developments like Cerebionics brain-computer interfaces mean even brain activity is being decoded and directly translated into machine commands. A thought can even lead to an order to kill, in this not-so-Brave New World.
Again, journalists can scrutinize this pillar through procurement and PR announcements. Defense deals like the US Defense Department’s Project Maven, can provide a starting point for research. Palantir won the US$480 million Pentagon Maven prototype contract and later confirmed its software was being used for targeting in Ukraine. Also, note that the AI company Anthropic has publicly flagged the risks of autonomous weapons and mass surveillance even while pursuing defense work, whereas OpenAI subsequently struck a deal with the US government meant to ensure its systems would not be used for either purpose. This might create the opportunity to find whistleblowers and ethical leaks in these ecosystems. But don’t hold your breath too much. As Tech Policy Press argues, “all lawful use” is too imprecise a phrase to do the ethical work companies want it to do. The term rarely explains who decides what is lawful, how compliance with international humanitarian law is assessed, or what accountability exists when those standards are disputed.
From Incident to System: What Reporting Works
In the end, reporting the practical workflow of technology-enabled warfare is far less dramatic than the science-fiction image of autonomous “killer robots,” but it goes much more directly to the heart of the matter. The reporter’s task is to move from a bombshell to the tech system that caused such harm. Ask what violations may have occurred and whether the incident crossed a threshold under international humanitarian law. Then work backwards.
What tech system was behind the event? Was a targeting database used? What facial recognition is deployed? Were there exports and imports and customs shipments? Much of this infrastructure becomes visible only through procurement. Reporters investigating military technology should, accordingly, become familiar with framework agreements, delivery orders and subcontracting structures, because the most important operational relationships are often buried there.
A framework contract may only establish a relationship between a ministry and a technology firm; the operational detail often appears later in cloud-service addenda, maintenance agreements, or consultancy contracts. Freedom of Information requests might detail the architecture of procurement.
The investigation by Article 19, which takes the January 2026 internet shutdowns in Iran as a starting point, showed how procurement made visible the underlying power structures, in which both state and corporate responsibility came to light. It investigates China’s role in the unprecedented Iranian controlled shutdowns following the December 2025 protests. By following the chain from state trade deals, to the Digital Silk Road to Chinese companies like Huawei and ZTE, it revealed how China has been instrumental in Iran’s internet control.
Another example is the Associated Press reporting on internal staff protests at Microsoft and Google. The investigation began with employee protests, which provided reporters with leads from current and former staff, eventually uncovering evidence that fuelled questions about breaches of corporate human rights commitments. Admittedly, activist employees are not neutral witnesses, but they may have access to valuable material, including screenshots, internal documents, emails and procurement records that can be independently verified. More broadly, journalists investigating military technology should think beyond conventional sources. Whistleblowers, former contractors, procurement officials, open-source researchers and technical specialists can all provide valuable leads.
Leaked datasets published by organizations such as DDoSecrets, as well as secure whistleblower platforms such as PSST, can also reveal procurement relationships, internal communications and technical documentation that would otherwise remain hidden. Such material should always be corroborated with other evidence before publication. At the same time, these investigations can expose sources to significant legal and personal risks. Journalists should therefore adopt robust source-protection practices from the outset, using encrypted communications, minimising identifying information and understanding the legal protections and limitations that apply in their own jurisdiction.
Another great example is Follow The Money’s investigation into “ethical” pension funds, which started from leaked documents on database reporting. The investigation sheds light on the chain of linkages from an investor’s money to human rights abuses in occupied territories in Palestine.
What these investigations have in common is their rigor. They tested witness testimony against procurement records. Tested procurement records against trade data. Tested trade data against evidence of deployment and use. Tested corporate statements against internal documents, technical specifications, and timelines.
In so doing, each source compensated for the weaknesses of the others. And, in this way, they allowed the reporters to move beyond a single, harmful horror to reveal the systems, institutions, and commercial relationships that make technologically-facilitated violence possible.
The Way Forward
The challenge for investigative and war reporters is no longer simply to document violence. It is to understand the systems that produce it. As warfare becomes increasingly dependent on commercial technology, cloud infrastructure, data systems, and artificial intelligence, responsibility is increasingly distributed across states, militaries, technology firms, subcontractors, and financiers. The result is that accountability becomes both harder to trace and easier for individual actors to deflect.
Journalism must respond to this by becoming more forensic, more technical, and more interdisciplinary. Follow the chain from harm back to the decisions, contracts, code, and institutions that made it possible. For this to be made possible will almost certainly mean it will be repeated. And, in an age of technological warfare, the most important story may not be the strike itself, but the system that enabled it and seems destined to do it again and again.
Iain Overton is a British investigative journalist, author, and human rights activist. He is the executive director of Action on Armed Violence (AOAV) and an Associate Professor at SOAS University of London, where he leads the MA Investigative and Human Rights Journalism pathway. A Peabody Award winner and former managing editor of the Bureau of Investigative Journalism, he is the author of “Gun Baby Gun,” an exploration of global gun culture, and “The Price of Paradise,” a history of suicide bombing and its impact on contemporary conflict. He holds a PhD from the University of Portsmouth based on his conflict reporting.