A NATO-Backed Drone Just Picked Its Own Target and Struck It. Here's Why That Matters.
A drone operating over a Swedish test range in January detected four objects, ranked an armored engineering vehicle as the highest-priority target, flew to it, and dropped an explosive on it, all without a human operator selecting that specific vehicle. The artificial intelligence system came from Scaleout Systems, an Uppsala University spin-off working on a low-cost loitering munition project called ALMA (Affordable Loitering Modular Ammunition), run by BAE Systems Bofors. The demonstration marks a significant shift in how autonomous weapons operate on contested battlefields.
What Changed in How Military Drones Make Decisions?
For years, the pattern in autonomous military systems has remained consistent: a human designates a general area or target category, then the AI handles the final approach and strike. Sweden's test moved that designation step onto the drone itself. At Winter Demo 2026 in Karlskoga, Sweden, in January, the ALMA system detected and geolocated threats using onboard computing, then ranked targets by priority without sending data back to a server or waiting for human approval.
What makes this test particularly significant is not just that the drone picked a target, but how it kept improving even when communication was cut off. In a June demonstration at a Swedish Air Force base in Uppsala, Scaleout ran a second test where the drone's computing node continued running inference and active learning after losing contact with the company's lab. When the connection was restored, it synced its improvements back to the system. Electronic warfare and jamming routinely break communication links on modern battlefields, which is why this capability matters.
"In principle, you can unlock collaboration between NATO member states," said Andreas Hellander, CEO of Scaleout Systems.
Andreas Hellander, CEO at Scaleout Systems
How Does This Technology Actually Work on a Drone?
Scaleout does not rely on frontier AI models from companies like OpenAI or Anthropic. Instead, it trains smaller computer-vision models sized for what a drone or forward workstation can physically carry. The system uses federated learning, meaning devices share model updates rather than raw sensor footage, keeping reconnaissance data on local hardware where it cannot be intercepted or jammed.
The specific problem this approach solves is model drift. A detector trained on desert imagery performs poorly over a city, and a war does not pause while someone retrains the model in a data center. Under the federated scheme, headquarters nodes retrain on aggregated battlefield data from several units and push revised models back out to the edge whenever a communication link opens. This work runs under a NATO project called FEDAIR (Federated Aerial Intelligence for Recon), inside NATO's Defence Innovation Accelerator for the North Atlantic.
Steps to Understanding the Accountability Gap in Autonomous Weapons
- Target Selection: The drone's AI system detects multiple objects, analyzes their characteristics, and ranks them by threat level without waiting for human confirmation of the specific target.
- Communication Loss: When jamming or electronic warfare breaks the link between the drone and its operators, the system continues operating independently and improving its models based on new battlefield data.
- Model Synchronization: Once communication is restored, the drone syncs its learned improvements back to the central system, creating a compounding capability that gets better over time without human oversight during the disconnected period.
- Accountability Question: Neither Scaleout nor BAE Systems has publicly answered whether an operator can still abort a strike once the communication link is severed, which is the entire design premise of the system.
What Do International Treaties Say About This?
Two weeks before Scaleout's demonstration became public, states party to the Convention on Certain Conventional Weapons agreed to a non-binding autonomy text in Geneva on September 5. The United States and Russia pushed late changes, with Washington seeking flexibility on human-judgment language. The agreed text has not been published, but advocates for restrictions say the agreement was substantially diluted in the final hours.
The U.S. does have a domestic rule. DoD Directive 3000.09, reissued in January 2023, requires that autonomous weapon systems be designed so commanders can exercise "appropriate levels of human judgment over the use of force." However, this directive governs only American programs and has nothing to say about a Swedish demonstration. The Seventh Review Conference in November will decide whether the September text becomes a negotiating mandate for a binding treaty, another rolled-over discussion, or nothing.
The Swedish case presents a strong engineering argument. Jamming breaks communication links constantly in Ukraine, and an aircraft that goes non-functional the second its link drops is an aircraft that has already been lost. Ukraine reached this conclusion from the bottom up, without a NATO accelerator behind it. Designing for a contested link is sound military engineering. It still does not answer who is accountable when the model ranks wrong, and that question is the one Geneva spent September attempting to define.
The learning loop, not just the strike itself, is what fundamentally changes the equation. A drone that picks its own target is not new, but a system that keeps getting better while nobody can reach it represents a compounding capability that nobody at the Convention on Certain Conventional Weapons has a clear definition for. Whether an abort command can still reach the aircraft once the link is gone is the question the November review conference will be judged on, and neither Scaleout nor BAE Systems has answered it in public.