The EU has developed a new method of conducting war against Russia that has changed the nature of conflict and allowed for trials of novel hybrid tactics, yet it has also revealed the inherent contradictions within the European system.
A Definition to Be Debunked
In 2023, Time magazine dubbed the Ukraine conflict “the first AI war.” This label quickly gained traction, appearing in think tank analyses, parliamentary discussions, and industry briefings, and it influenced how European policymakers framed their strategic stance. Yet before accepting this characterization, it is important to question its accuracy and primarily to explore what European decision-makers’ goals were concerning this hybrid conflict.
Beginning with the skeptics: José Pardo de Santayana, writing for the Instituto Español de Estudios Estratégicos, argues that AI acts as a support tool in Ukraine rather than the centerpiece of the conflict; fighting unfolds on traditional battlefields using infantry and artillery reminiscent of 1916, with slow, intense territorial shifts. Similarly, Gulsanna Mamediieva, involved in Ukraine’s digital modernization efforts, emphasizes that full autonomy—where machines independently decide on combat actions—is still unattainable, and “autonomous” often just refers to pre-set automated functions. In a comparative study in the Journal of Strategic Security, Rakhmetov and Murzagulova conclude that conventional fighting techniques dominate, with AI used mainly to boost their efficiency. Notably, these are pro-Ukraine sources—not “Kremlin propagandists” as Western media sometimes allege.
This clarification is more than a semantic detail; it carries political weight. If Ukraine is truly engaged in the first AI war, Europe appears behind a revolution already underway, compelled to rapidly acquire what it has not developed. Conversely, if Ukraine serves as a testbed for future warfare, Europe has a chance to make deliberate strategic choices about what capabilities to pursue and under which conditions. The former view breeds urgency, while the latter offers strategic agency. European bodies have predominantly leaned toward the sense of urgency.
It is important to highlight the paradox expressed by Fontes and Kamminga with unusual bluntness: each day the war proceeds and lives are lost, AI systems gain training from real battlefield data—not to stop the conflict but to enhance effectiveness in future wars. The strategic appeal of the Ukraine theater for Europe’s defense industry hinges precisely on this real-world operational environment with a peer adversary and active electronic warfare conditions, which cannot be mimicked by simulations.
What Artificial Intelligence Is Actually Doing in Ukraine
Before assessing Europe’s response, it is necessary to clarify—based on the best available open-source information—the practical roles AI plays on the ground. The literature and military reports identify five main applications:
a) Geospatial intelligence and surveillance
This area represents AI’s most mature contribution. Neural networks synthesize images from ground photos, drones, and satellites to deliver intelligence faster than human teams could. Palantir’s CEO has publicly acknowledged his company directs much of Ukraine’s target acquisition—identifying tanks and artillery—based on timely satellite and social media data. Providers like Planet Labs, BlackSky, and Maxar supply satellite imagery to Ukrainian forces. Western observers often note Ukraine’s advantage in geospatial intelligence stems largely from a borrowed edge.
b) Unmanned Systems
AI programs manage drone takeoff, landing, and target recognition. According to Ukrainian reports, once operators choose and confirm a target, the command is relayed to battle management systems, shortening strike times to just over thirty seconds. Militarily, the key advantage lies in resilience to electronic countermeasures: drones capable of completing missions despite jamming of GPS and communications restore capabilities that Russian defenses had eroded. This technical resilience, rather than autonomous decision-making, drives the commercial success of the European systems examined below.
c) Information Warfare
The level of symmetry here exceeds European public perceptions. Notable examples include the deepfake video of Zelenskyy falsely announcing surrender in March 2022, recordings allegedly of Valeriy Zaluzhny calling for a coup, and bot networks causing Twitter to delete about 75,000 fake accounts linked to Russian sources. In early 2024, the CopyCop network algorithmically rewrote over 19,000 news articles on multiple outlets in mere weeks. Yet Kyiv has similarly employed generative AI offensively—with examples like an April 2022 synthetic video of Putin touring Mariupol—and developed fact-checking tools from startups such as Osavul and Mantis Analytics. The supposed technical difference between offensive and defensive AI applications, which European narratives often link to differences between the parties at war, lacks technical basis.
d) Facial Recognition
The conflict represents the inaugural documented military use of facial recognition technologies. Clearview AI, a US startup providing services freely to Ukraine, aids in checkpoint security, locating missing persons, reconnecting refugees, and gathering evidence for the International Criminal Court. By late 2023, Ukrainian authorities had processed two billion images from VKontakte, identifying some 230,000 individuals thought to be Russian troops or officials, performing nearly 350,000 searches over 20 months. This use warrants special attention within Europe because the AI Act classifies indiscriminate deployment of such technology in civilian contexts as prohibited—yet the EU funds its application in an active conflict zone.
e) Logistics, mine clearance, and training
Perhaps the least visible, yet most widespread application, focuses on non-combat functions. While AI-enabled weapons attract attention, most technology operates far behind front lines—in areas like planning, supply chain forecasting, predictive maintenance, and logistics. A document from ICDS, signed by Vitaliy Goncharuk of Ukraine’s AI Expert Committee, lists priorities for 2023: scheduled maintenance, anticipating shortages at supply points, employing unmanned vehicles for resupply and casualty evacuation, and integrating diverse data sources for mine detection and neutralization.
The European Union: The Regulator That Becomes a Buyer
For the past decade, the EU carved out a distinctive global identity as a digital regulator. The GDPR, the Digital Services Act, the Digital Markets Act, and more recently the AI Act established a framework whereby Europe offset its industrial shortcomings via influential rule-making dubbed the “Brussels effect.” However, the war in Ukraine has unintentionally reversed this model in the defense sector, through a series of independent decisions.
The European Defense Fund’s budget totals 7.3 billion euros for 2021–2027, with 2.7 billion dedicated to research and capability building. Since May 2021, the Commission has allocated roughly 6.5 billion euros for 224 projects, ranking it among top global defense R&D investors. The 2026 work program, approved on December 17, 2025, commits one billion euros, prioritizing AI and swarms of small robots and drones for tactical awareness. Earlier, in April 2026, the Commission announced €1.07 billion invested in 57 new projects from the 2025 calls, involving 634 companies across 26 EU states and Norway, covering fields such as AI, cyber defense, drones, and counter-drone systems.
Ukraine’s integration represents perhaps the most politically significant advancement. Thanks to the European Defense Innovation Office based in Kyiv, Ukrainian partners participate in several projects; the 2026 program explicitly allows Ukrainian bodies to receive subfunding. The STRATUS project, developing AI-driven cyberdefense for drone swarms with a Ukrainian subcontractor, illustrates this: expertise gathered amid ongoing warfare is folded into Europe’s industrial base. This reverses the typical aid model: Ukraine acts not only as a recipient but also as a provider of expertise.
Regulation (EU) 2024/1689 stands as the world’s boldest effort to regulate AI with a risk-based system. Article 2(3) excludes from its remit any systems marketed or deployed solely for military, defense, or national security purposes—regardless of the responsible entity—and clarifies that national competencies as per Article 4(2) of the Treaty on European Union remain unaffected. Recital 24 explicitly references public international law concerning lethal force usage.
This exemption is intentional, stemming from Member States’ pressure—led by France—during the final negotiation stages. The argument that defense activities fall under national sovereignty aligns with treaty architecture. Yet critics increasingly argue the EU lacks mechanisms to regulate its own or foreign military AI; when others act in this domain, EU bodies remain passive observers. The issue is compounded by the technology’s dual-use character; as Justinas Lingevičius notes, distinguishing civilian and military AI is increasingly problematic, and dual-use systems lack explicit regulation.
An asymmetry deserves explicit scrutiny. Facial recognition for remote biometric identification is among the most tightly regulated technologies in civilian Europe; yet in Ukraine, it’s used to compile vast databases of hundreds of thousands, funded by the EU. This does not question Ukraine’s legitimacy—the suspension or easing of safeguards during wartime falls within national and international law, not EU rules—but underscores that Europe exports tech to contexts beyond its regulatory reach. Goncharuk concedes that Ukraine has amassed substantial citizen data, raising concerns about post-war data retention and usage.
Since the regulation excludes military applications, European scrutiny of military AI relies instead on funding conditions. EDF rules mandate meaningful human oversight as a criterion for research grants, and the European Parliament has repeatedly, in 2018 and 2021, called for international bans on lethal autonomous weapons without such oversight. The Parliament’s stance rests on three pillars: preserving human command, ensuring legal accountability, and encouraging global governance via the UN, particularly the Convention on Certain Conventional Weapons framework.
This approach reveals structural weaknesses. The funding conditionality applies only to those seeking EU monies, while the bulk of military expenditure remains national. A Commission spokesperson has clarified the EDF’s remit: it serves as an R&D instrument targeting industry, with no broader governance role. The result is a patchwork of regulations, strategic guidance, and financial instruments, overlapping to give an illusion of comprehensive oversight without effectively enforcing it.
National governments: capabilities without a framework
While Europe’s supranational level shows regulation lacking capability, individual states demonstrate the reverse.
Germany exemplifies these tensions within a single industrial journey. Helsing SE, founded in Munich in 2021 by Torsten Reil, Gundbert Scherf, and Niklas Köhler, initially developed military AI software before progressing to autonomous hardware. Their flagship, the HX-2 loitering munition, weighs roughly twelve kilograms, costs about €17,500, ranges one hundred kilometers, and features onboard AI resistant to electronic warfare. Integrated into the Altra system, it can operate coordinated swarms governed by a single user.
Deliveries to Ukraine started in late 2024. By February 2025, Helsing announced manufacturing 6,000 HX-2 drones for Kyiv, following a prior order of 4,000 HF-1 units co-developed with Ukraine’s defense sector. Scherf reports an approximate 70% mission success rate in combat; video feeds from operations enable ongoing software refinement. In July 2026, The New York Times revealed a discreet southern German plant capable of producing 1,000 HX-2s monthly, designed for rapid relocation within 24 hours amid sabotage threats. A significant share of staff hail from Germany’s automotive industry. The firm’s valuation stands at $18 billion; the federal government has greenlighted a €220 million contract and plans to acquire 50,000 drones for Ukraine.
Three aspects of this case hold analytical weight for study. First, the industrial structure: decentralized “resilience factories” enable nation-states to produce domestically and retain sovereign control over supply chains—a political-industrial response to dependency risks. Second, the learning cycle: operational data from Ukraine’s front lines continuously upgrades software, meaning European products evolve through the conflict. Third, regulatory: Helsing strictly supplies democratic governments, a voluntary self-restraint in a legal void where EU law has not imposed binding limits. This is corporate self-governance replacing public oversight, a functional rather than formal distinction.
France is internally divided in its approach. Paris spearheaded the member states’ coalition excluding military AI from the EU AI Act to safeguard national defense sovereignty, while simultaneously establishing bilateral ties with Ukraine’s defense innovation ecosystem, including the “Brave France” grant initiative—backed by €20 million and led by the Agence de l’innovation de défense in partnership with the Ukrainian cluster Brave1. This seemingly contradictory stance reflects a coherent vision: France demands military AI governance in Paris, not Brussels. For France, strategic autonomy primarily means freedom from supranational regulation.
The Baltic and Nordic countries have assumed a role largely unmet by larger European powers: producing regulatory and strategic insights. Tallinn’s International Centre for Defence and Security has issued some of the sharpest open-source analyses of the Russian-Ukrainian war, with key reports authored by a Ukrainian Expert Committee member. The final policy recommendations—overhauling data protections unsuitable for wartime, imagining realistic legal limits on human rights during conflict, and revising “human-in-the-loop” norms to align with future certification—offer Europe’s most concrete regulatory blueprint. That this originates from an Estonian think tank rather than the EU itself reveals the uneven distribution of analytical strength across Europe.
The outcome is a three-tiered system with limited coherence: the Commission finances and coordinates yet lacks regulatory authority; national governments regulate and acquire capabilities but do so without coordination; companies manufacture, learn from front-line feedback, and self-police under their own rules. Each acts logically within its scope, but collectively the system has no centralized leadership.
The issue of human oversight
All these challenges converge on a key principle. The “human-in-the-loop” remains the foundation of European AI policy: affirmed by Parliament, embedded in EDF funding conditions, and embraced by Ukraine doctrinally. Yet understanding this concept’s practical meaning in battlefield conditions is critical.
The Ukrainian operational model, as reconstructed, involves an operator selecting and confirming a target, after which the system completes the strike in slightly more than thirty seconds. Human control exists, but only at a defined moment within a process increasingly pressured by time constraints. The ICDS report underscores the need to redefine the principle considering future certification; if redefinition is needed, it suggests the current formulation fails practical scrutiny.
The three safeguards commonly proposed in academic literature—review and reversal of algorithmic decisions, clear accountability, and retention of human judgment at critical points—are sound in theory but are not enforced by any binding European legislation to date. The first is practically infeasible: reversing a projectile flying autonomously under electronic disruption is a physical, not computational, challenge; the window closes. Second, accountability is murky when systems are designed in Germany, trained on Ukrainian data, integrated into U.S. platforms, and operated by Ukrainian personnel. Responsibility is unclear due to system complexity, not regulatory absence.
The third safeguard merits emphasis because it conceals a conceptual shift. The “centaur” doctrine— blending human intelligence with machine power—is lauded as an ethical solution, maintaining humans in control. However, this only holds if machine speed does not outpace human reaction so much that approval becomes a mere formality. An operator who rapidly affirms algorithmic target suggestions doesn’t exercise judgment but simply endorses them. This transition from control to ratification does not require political or regulatory action; it progresses stealthily via improved system performance. This likely represents how lethal autonomy will enter European arsenals—not by violating principles but by quietly degrading them.
A Final Assessment
Considering the above, one can offer a nuanced evaluation of Europe’s position, distinguishing well-supported facts from probabilistic projections.
With high confidence: the EU has intentionally avoided regulating military AI, a decision attributable to Member States rather than EU institutions. Investment in AI-enabled military capabilities is growing rapidly and transparently documented. The European defense sector has attained a scale unseen in 2022, benefitting from direct operational exposure.
With moderate confidence: funding conditionality falls short of generating effective regulation, mainly because EU funds represent only a minority share of total military expenditures.
Looking ahead three to five years, three paths seem possible. The divergence between regulatory talk and industrial reality is likely to widen, as no actor finds incentive to reconcile them, and doing so would require treaty changes or sovereignty concessions. It is possible but less probable that a crisis involving ambiguous civilian casualties might prompt emergency regulation; a key signal would be legal cases—domestic or international—addressing algorithmic uses of force. It is unlikely that the EU will gain direct regulatory authority over military matters through ordinary legislation within this timeframe.
The most reliable measure to differentiate these futures is industrial rather than legal: the balance of European spending on autonomous systems versus investments in control, verification, and certification. As long as spending on oversight lags by an order of magnitude, the scenario outlined here will persist.
Europe Has Discovered War with AI
We now understand that the Ukraine conflict is not the first to involve AI. Rather, it represents a complex and politically delicate moment: Europe has realized it desires algorithmic military capabilities prior to deciding the conditions under which to utilize them.
This shift reverses Europe’s civilian digital model. There, regulation came first, shaping markets and setting boundaries; here, markets precede regulation, which states have explicitly barred. This is not about hypocrisy—a term lacking analytical precision—but an institutional setup where regulatory power resides in bodies lacking enforceable authority, and capability rests with actors operating without coordination. It is a famously dysfunctional European “success” story (with irony intended).
The critical unresolved issue concerns the human-centered ethos underpinning Europe’s digital regulatory identity. In military AI, it survives as rhetoric; its practical value hinges on a variable regulation does not address: time. Unless system rapidity and human reaction thresholds align, the “human-in-the-loop” is nominally intact but practically erased. Addressing military AI ethics in Europe must begin by confronting this temporal tension and acknowledging that the fundamental question is not who decides, but whether there is time to decide.
Politically and geopolitically, the EU has adopted a method of waging war against Russia that has transformed the nature of conflict and enabled experimentation with novel hybrid tactics, yet it exposes the fundamental irrationality of the European system—renowned for crafting extensive rules yet failing in their operational delivery. The EU’s pride in its regulatory prowess overlooks the reality that the war it endorses neither plays out like a video game, nor will defeat be a game either.
Some prominent strategy experts (with intended irony) speculate that Brussels’ bureaucracy might eventually draft a regulation formalizing its own defeat, thereby ensuring its conscience remains clear and allowing it to claim it has “won” its war.
