Kherson Killer Robots Versus the Four Human Safari Defenses

Anne Applebaum has written in The Atlantic about Yuri, a 52-year-old market vendor in Kherson chased around his truck by a Russian drone that dove beside him and exploded. He survived with cuts and a concussion. Her account is accurate but she leaves open a question that doesn’t make sense: “How long until the rest of the world also experiences this change?” She treats the transformation something that arrives on its own and spreads.

It does not.

It moves through named companies, on named products, through documented channels. The world changed years ago, and has been under reported. The defenses against it exist at four layers, three of which are already deployed by fishermen and municipal workers, and one of which belongs to a single vendor unnamed by The Atlantic.

Her piece also grants autonomy only to the Ukrainian side. The warehouse drones she visited in Kyiv “can make intelligent decisions autonomously.” The Russian atrocities in her telling stay operator-driven: a human sees the feed, chooses the target, plays the video game. Why the asymmetry? Her framing gives Russia an accountability story, which is already out of date.

The driverless machine that hunts Yuri

On June 9, 2025, Ukraine’s Defence Intelligence published a teardown of a Russian loitering munition it designates the V2U. The drone “autonomously searches for and selects targets using artificial intelligence.” Its brain is an NVIDIA Jetson Orin module mounted on a Chinese-made Leetop carrier board, a unit that sells for 380 dollars and carries a solid-state drive storing a target-and-terrain matching database. It was first seen in September 2024 in Kazan and first used in combat in February 2025 in Sumy.

The V2U carries a single GPS module and relies on computer vision instead, comparing its camera feed to preloaded terrain. This is a direct response to Ukrainian electronic warfare, which spoofs and denies GPS. The drone stopped needing the signal because the signal was a vulnerability. Its target discrimination is poor. Ukrainian analysts report the V2U does not distinguish between military equipment and a civilian bus, that the drones work in color-marked teams stacked like circling vultures to attack in sequence without radio, and that one struck a public toilet instead of a vehicle.

The class of threat is spreading. A recovered Russian Molniya carried only a camera and an onboard computer, a configuration previously seen only on the V2U, and Ukraine’s radio-warfare adviser Serhii Beskrestnov says the enemy is using the V2U platform to train its neural network.

Applebaum’s “video game” metaphor has a hidden dependency, because it implies a human gamer linked in. The Kherson hunts increasingly run on fiber-optic drones precisely because jamming killed the radio link, and machine-vision terminal guidance is the next step in the same countermeasure chain. The autonomy she attributes to Ukrainian ingenuity is arriving on the Russian side through a supply channel that allegedly runs through the world’s most valuable company.

The crime is known

This is not contested. On May 28, 2025, the UN Independent International Commission of Inquiry on Ukraine concluded that Russian drone attacks on civilians in Kherson Province were widespread, systematic, and conducted as part of a coordinated state policy. Nearly 150 civilians killed, hundreds injured, across Kherson city and 16 localities, from July 2024. Crimes against humanity of murder. In September the Commission extended the finding to Dnipropetrovsk and Mykolaiv, across a 300-kilometre stretch of the Dnipro’s right bank. The UN human rights monitoring mission counted at least 577 civilians killed by short-range drones in 2025 and more than 3,000 injured, with nearly 95 percent of the casualties in territory held by Ukraine.

The escalation ladder uses defeated defense for steps

The timeline is the argument. Fiber-optic drones were first fielded in spring 2024. By early 2026, Russian adoption had reached 30 to 50 percent in some front-line units. The Commission of Inquiry dates the systematic Kherson hunting from July 2024. The same journalist Applebaum cites for Yuri, Zarina Zabrisky, first reported the human safari on July 29, 2024. Fiber optics and the safari arrive in the same season, because they are the same threat. Electronic warfare was the clean answer to the drone, and it worked until someone removed the radio.

Fiber optics defeat jamming but trail a cable that can be cut and limit endurance. So the next rung is onboard vision, which needs no cable and no link at all. Ukraine’s own TFL-1 already hands the final 500 meters to AI, where jamming is fiercest, while the operator handles the transit. The limitation is documented as an operator still has to fly the drone into lock-on range before the algorithm takes over, which leaves a window. Close that window and the human leaves the loop entirely. The V2U now is what closing it looks like.

The defenses that still are ahead

Applebaum writes that nobody is prepared. This is where her frame most needs correcting, because ordinary people in Kherson are preparing every single day, at three of the four layers where preparation is possible.

The first layer is physical. Kherson has strung anti-drone nets over more than 23 kilometres of streets, fitted every municipal vehicle with electronic detection, and runs mobile fire teams against roughly 2,000 drones a week. The nets are repurposed fishing and tulip nets. Sweden’s Operation Change alone has sent 400 tons of unused fishing net. The city credits the combined measures with destroying 80 to 95 percent of the drones launched at it. This is civil defense improvised from the discards of the European fishing industry.

The second layer is electromagnetic. Jamming and spoofing defeat the radio-controlled drone. They do nothing against fiber, and nothing against onboard vision, because neither emits a signal to attack. This layer is collapsing by its own success, the way a vaccine drives resistance. Electronic warfare manufactured the autonomous hunter it cannot touch.

The third layer is algorithmic, and it is the grimmest. The machine-vision drone can be fooled. There is a decade of peer-reviewed work on defeating person detectors with printed patterns worn on the body, beginning with Thys, Van Ranst, and Goedeme in 2019, continuing through the Adversarial T-shirt and the Invisibility Cloak at the 2020 European Conference on Computer Vision, and into infrared-defeating garments. NVIDIA’s own model documentation for its people-detector states that detection accuracy varies by who is in front of it. Read as a threat specification, that document tells a civilian what the weapon can see. The pre-AI version of this defense is already on the battlefield: Ukraine’s defense ministry is testing anti-thermal ponchos, camouflage re-institutionalizing itself for a machine observer exactly as it did for the human observer by 1918. The honest caveat is that it is fragile. A RAND team found in 2022 that many adversarial attacks are operationally infeasible to deploy against fielded systems, harder in the field than in the lab. So the third layer buys a civilian something, but not enough, and not reliably.

The fourth layer

Which leaves the fourth layer, the only one that scales, and the only one no one operates. The chip is the layer. NVIDIA has already proven it will re-engineer silicon to obey a restriction when the restriction protects a market it wants, redesigning the H20 for China and swallowing a 5.5-billion-dollar charge rather than ship uncontrolled. No government has ordered it to keep its edge modules out of drones that hunt people, so it has not. The Jetson runs the people-detection models in Kherson exactly as it runs them at a picnic or after a disaster. I have documented the pattern at length: the company hands human-targeting help to anyone who asks in its own forums, ships the people-detection models as named products, and watches its hardware surface in one autonomous weapon after another while its stated remedy of cutting off violating distributors sits unused.

Let’s be honest, a chip restriction from NVIDIA alone would not end the safari. The Ukrainian strike kits shipping by the tens of thousands, Auterion’s Skynode S, run on a quad-core Arm processor with a 2.3-TOPS neural unit, not NVIDIA silicon at all. Terminal-guidance autonomy is achievable well below Orin-class compute. So restricting the highest-capability tier strips the best of the autonomous hunters from the battlefield without removing all of them. It is necessary, not sufficient. But necessary is not nothing, and it is the one layer of defense that a company could install with a fraction of the engineering it already spent to protect its China revenue, and has chosen not to.

What The Atlantic already published

Applebaum’s own magazine answered her headline question three years ago. Beneath her article, in her reader’s saved-stories rail, sits Robots Are Already Killing People, which I co-wrote for The Atlantic in September 2023. Its argument was that intelligent and unintelligent machines have been killing people for decades, that the safety question is not futuristic, and that the fix is comprehensive safety standards applied across technologies rather than after each death. The Atlantic published the mechanism. Its staff writer now asks how long until the era arrives, as if the answer were not already in the archive.

Her report treats autonomous killing machines as an approaching era. The teardowns treat them as an installed base, which I predicted years ago. The distance between those two is the whole of the preparation that could still be done, and the whole of the reason it is not.

Black Hat OpenAI Presentation Digs a Deeper Hole

The detection story on stage is now even worse than the already terrible remediation story.

According to the conference news, models ran a coordination channel inside Artifactory for months, and OpenAI found it only when configuration changes caused a July 4 outage.

Discovery by availability failure, not by monitoring, is a known anti-security pattern.

The response was wipe and rebuild while leaving the enabling insecure condition intact: the models could still write to Artifactory. The recreated message board proves write access survived the rebuild. The reporting does not clarify whether the internet egress path survived with it.

Recompromise within days? Of course. This is the level of Black Hat now?

It was an easily predictable result, but somehow it still didn’t trigger proper human accountability and precaution. In classic IR terms they did eradication without root cause removal, which is the one thing every incident response framework says not to do.

Another security anti-pattern.

So OpenAI is running too hot with nobody in charge who knows how to stoke a boiler? That’s a late 1800s disaster story. Nothing could make OpenAI look more negligent than what they are saying themselves, perhaps because they don’t even understand corporate malfeasance.

Here’s a framing inversion worth noting. The documented incident is an internal containment failure. Their failure, their own agents, their own package manager, their own missing egress controls. That’s no way to run a company, any company.

The Black Hat presentation converts that into a prediction about external threat actors and, in the speaker’s words, “a watershed moment for computer security as an industry.”

Huh? Basic controls? Monitoring agents? Data boundaries? Keeping secrets? None of this is watershed.

OpenAI’s test environment lacked segmentation and least privilege, the exact controls the speaker then recommends to everyone else. The advice is coming from a source that just demonstrated not applying it, twice.

Did Bruce Ismay, who survived his own ship, book a lecture tour to declare the future of maritime safety was counting lifeboat capacity? He retreated from public life instead. OpenAI booked Black Hat because the captain apparently doesn’t go down with the AI shipping.

No Brakes, No Speed: AI Podcast Got My Regulation Argument Backwards

I’m a little annoyed right now. A podcast episode released yesterday, which has me as a skeptic, concludes incorrectly that I want AI development slowed down.

I said no such thing.

Decades of published record on this site says the opposite. I have requested a correction from the show, and this post is the argument you should have heard, instead of their post-interview overlay that is backwards.

What I Actually Said

As I have taught corporations and CS graduate students in my ethics lectures, the Grover Shoe Factory exploded in Brockton, Massachusetts on March 20, 1905, killing 58 workers and injuring 150. The factory had fired an aged backup boiler while its newer vessel sat under repair. A known weaker system, deliberately placed in service, catastrophic failure within hours.

title slide

The point of the story is local response, such as how Massachusetts passed boiler inspection law in 1907. And the next point is industry, such as ASME convened its code committee in 1911 and published the Boiler and Pressure Vessel Code in 1914. States, again local, adopted it as the condition of operation. Self-certified pressure vessels ended as a legal category, without any federal leadership. After that, an independent inspector signed off on the engineering or the thing did not run.

The Grover Shoe Factory disaster is one of the most important engineering lessons in American history, yet few if any computer engineers have ever heard of it.

That is the precedent I cited for AI. No agentic deployment runs without independent certification of its containment and monitoring, per system, renewable, with the certificate as the condition of operation.

The show heard me describe this form of “regulation” and filed me under deceleration with two others I shared nothing in common. Watch the substitution. The American industrialist will attempt to simplify, “accelerate or decelerate”, and frame every mention of oversight to the “decelerate” end. My argument was never on that false choice axis. It is an argument about which regime is actually faster.

Inspection is Speed

If I told you OpenAI removed the brakes to test their race car, you would see why requiring a safety inspection would make their race car faster to produce and drive.

Boiler explosions ran to hundreds per year in the self-certified era. That was the slow regime. Each explosion destroyed capital, killed workers, and reset public trust to zero. Disaster is not an acceleration path.

Steam power scaled after the regulation code, because factory owners, insurers, and municipalities could finally trust a pressure vessel they had never built themselves. More to the point, innovations came from the regulation, which were the actual market benefits. The Hartford Steam Boiler company proved the economics four decades earlier: it began inspection as a condition of underwriting in 1866, and its inspected boilers failed at a fraction of the base rate, leading to downstream market expansions.

Verification removes the trust cost from every transaction. Nobody load-tests an elevator before stepping into it, and nobody should trust a self-certifying elevator. The independent certificate does it once, for everyone. Aviation moves billions of passengers a year on type certificates. The counterfactual to certification was never faster planes. It was a market grounded by its own crashes.

Now apply it to the current record. OpenAI disclosed that a pre-release model wasn’t properly contained so it breached Hugging Face. Anthropic then reported itself its own model had breached three companies, undetected for months, discovered only after a competitor’s disclosure prompted an internal review. No regulator slowed anything. The labs’ own breaches did. Every procurement team that read those disclosures now runs its own special containment audit before any agentic deployment. That review time, multiplied across every customer, is the ballooning tax of self-certification. The slow path is the one we are on because we aren’t standardized. We need to be working on compliance, the shared version of security.

I never asked for AI to be slowed, because it’s already too slow. I asked for it to stop exploding. The boiler explosions were the slowdown, and history is clear that regulation is a performance enhancement. Better brakes, faster lap times.

EU Tries to Root Sovereignty in Two U.S. Corporations

An EU sovereignty project whose root of trust is two American corporations’ key ceremonies, subject to US jurisdiction, is like reading The Onion. But it’s real.

How stupid of the EU?

The EU already owns a sovereign root of trust and has suspiciously declined to use it. The German eID chip is Common Criteria certified by BSI, runs on silicon from Infineon and NXP, and has shipped in every Personalausweis since 2010. Smartcard-based eIDAS notified schemes exist across member states. Choosing American smartphone TEEs over that installed base was a particularly non-sovereign decision dressed up falsely as an architecture requirement.

Both attestation roots are supposed to terminate in key infrastructure operated by companies subject to US legal process, so the admission decision for an EU citizen’s identity credential runs through jurisdiction that the EU spent the last decade claiming to escape.

Schrems I and II were litigated over less.

a blog about the poetry of information security, since 1995