The next military AI breach will look like normal model behavior. Adversaries poison the data, spoof the sensors, or corrupt one input. Defense is adversarial testing and human review.
The next military AI breach will not look like a breach. It will look like a model behaving exactly as it was trained to, because an adversary quietly poisoned the data, spoofed the sensor, or corrupted the one input the system trusted.
That is the asymmetric logic of military AI in 2026. The U.S. is now spending at a scale that would have looked fanciful a decade ago. A Brennan Center report published in March 2026 puts American AI-driven military programs on track to surpass $75 billion in the coming years, excluding classified work. Russia and China are spending heavily alongside. But the cheapest attack on a $75 billion fleet does not cost $75 billion. It costs the price of finding the one input an adversary's model was not built to distrust, and feeding it something the system reads as normal.
In March, the U.S. military confirmed it has used advanced AI to help identify and prioritize targets in Iran, drawing on satellite imagery, social media, military drones, and sensor feeds to assess legality and strategic weight. The point is not whether the system worked. The point is that the system is now part of the targeting chain, which means the data feeding it is now a battlefield. The targeting model is a sensor-fusion product: different sensors are combined by software into a single picture, and if any of its inputs can be moved, the output moves with them.
Mahmoud Javadi, a Ph.D. researcher at the Centre for Security, Diplomacy, and Strategy at Vrije Universiteit Brussel, names the attack surface in plain engineering terms. There are four ways to break an AI agent, and each one is cheaper than rebuilding one. Hack the system directly. Poison the training data so the model learns the wrong lesson. Manipulate the model after deployment. Confuse the sensors that feed it in real time. None of these require a peer military. They require an adversary who understands the model better than the people who deployed it, and a moment in which the model's confidence is the only thing standing between a sensor reading and a strike.
War is messier than any model is built for. "War is messy, the data is incomplete, the enemy practices deception, and AI systems can make strange mistakes," Javadi writes in EE Times. "Even a small error in a military situation becomes very serious, especially for targeting and threat surveillance." The error is not a software bug. It is a structural property of how these systems are built and how they fail.
The Russia-Ukraine war gave the world its first sustained look at AI in modern combat on both sides. Ukraine has used AI for geospatial intelligence, surveillance, logistics, and unmanned operations, often under conditions where a spoofed GPS signal or a manipulated drone feed was the difference between a hit and a civilian casualty. AI agents are increasingly paired with the growing use of drones in modern warfare, which means the model is now in the same loop as a kinetic munition. The pattern is not hypothetical. It is the operational baseline for the next conflict, including the one the U.S. just acknowledged against Iran.
The policy leg is the part the spending debate usually misses. A 2023 Government Accountability Office review found that the Department of Defense lacked department-wide guidance to inform AI acquisitions, a gap that includes the cyber-hardening standards a targeting system is supposed to inherit at contract award. The Brennan Center's research places Project Maven and the Defense Innovation Unit at the center of how the Pentagon buys AI targeting and drone technology. If the security model lives in the contract, and the contract has no shared standard, then every vendor is solving the same problem in isolation, and the adversary only has to beat the weakest one.
The constructive turn is unglamorous and specific. It means adversarial red-teaming, or stress-testing the model against inputs built to make it fail, before deployment. It means sensor hardening, building receivers and cross-checks that reject false signals, against spoofing. It means model validation under degraded data conditions, to catch the strange mistake before the system reaches a strike authorization. It means disciplined human-in-the-loop review, a person whose job is to distrust the model's confidence in exactly the conditions where it should not be trusted.
That is the engineering property the $75 billion figure cannot buy. The country that wins the military AI contest will not be the one with the smartest model. It will be the one whose inputs the adversary cannot quietly corrupt. The next test is the one already running in Iran, where the targeting system the U.S. confirmed using this spring is operating on the same data adversaries have every reason to try to break. The first confirmed attack on that pipeline will be the moment the procurement debate catches up to the engineering one.