Connect with us

AI

Golden Dome AI Can Flood Operators Without Four Fixes

Ukraine cut fire missions to under a minute. Golden Dome’s extra interceptors can bury crews unless missile defense AI meets four tests.

Published

on

GIS Arta cut Ukraine’s artillery cycle from 15 to 20 minutes of manual work to under a minute, the kind of missile defense AI the Pentagon now wants at continental scale. Batteries mark themselves open for jobs. Sensors dump coordinates. Software assigns the shot.

Lt. Gen. (Ret.) Trey Obering, a former director of the Missile Defense Agency and now a Booz Allen senior executive advisor, says that loop does not get kinder when you stretch it across ground, sea, and a planned orbiting interceptor layer. More tracks can land on the same crew.

The Rideshare That Cut Fire Missions to Under a Minute

Early in Russia’s full-scale invasion, Ukrainian units faced more guns, more armor, and more mass. They answered with software. GIS Arta, built by Ukrainian programmers after 2014 and refined in combat, is a geographic fire-control app. Forward observers, drones, radars, and even smartphones feed it. The app then hands a fire mission to a battery that is in range and free.

A New America analysis described that assignment as an Uber for artillery matching algorithm. Guns check in the way drivers go online. A touch interface highlights units that can take the target. The same write-up said Russian artillery outnumbered Ukrainian pieces 20 to 1 on some stretches of front, so speed and pairing had to replace volume.

WHAT THE APP ACTUALLY JOINS

  • The sensors: Drone video, phone reports from observers, counter-battery radar, and satellite pictures all land on one map.
  • The assignment: The software picks a unit by target type, range, and munition, then sends azimuth, distance, and fuse data to a tablet or laptop.
  • The exit: After the round goes, the system supports shoot-and-scoot so the battery can move before return fire arrives.

Users reach it on phones, laptops, and hardened notebooks, often through military radios, cell networks, or Starlink. That is a local kill web, not a national missile shield. It still shows what happens when pairing is faster than a staff meeting. Manual coordination that ate 15 to 20 minutes became possible in under a minute, Obering wrote, and the new firing solutions often confused Russian counter-battery crews who expected clustered guns.

The shift he draws from that war is blunt. Platforms give way to distributed networks. A linear kill chain gives way to several shots at once. People still authorize fires, but software does the matching.

Golden Dome Stacks That Loop Across Continents and Orbit

The U.S. version of that idea is Golden Dome for America, the homeland missile shield ordered in January 2025 as Iron Dome for America and later renamed. It is supposed to stitch together existing Patriots, THAAD batteries, and Aegis ships with new low-cost land interceptors, space sensors, and a proliferated fleet of space-based interceptors in low Earth orbit.

Gen. Michael Guetlein, director of Golden Dome for America, has said the homeland problem is getting those weapons to act as one system across a lot of geography. Space Force planning calls for an on-orbit interceptor that can plug into that design by 2028, with the wider shield still drawn out to 2035. In April 2026 the service awarded prototype work worth up to $3.2 billion across 12 companies, Booz Allen among them, and set ground tests for 2026 and orbital flights for 2027.

Guetlein’s public cost for the objective design over the next decade is $185 billion. The Congressional Budget Office, working from the original executive order rather than a finished Pentagon blueprint, put a notional national system at about $1.2 trillion over 20 years in 2026 dollars. That is a different clock and a different stack, and the office said it could not price the classified Golden Dome architecture itself.

CBO’S NOTIONAL FOUR-LAYER SHIELD

Layer Scale 20-year cost
Space-based interceptors 7,800 satellites $743 billion
Upper wide-area sites 3 sites $46 billion
Lower wide-area sites 4 sites $29 billion
Regional sectors 35 sectors $187 billion
Space tracking constellation 1 constellation $90 billion

Self-defense at existing sites and a research pot bring the 20-year total to about $1.2 trillion. The space interceptor layer is about 70 percent of buy costs and about 60 percent of the whole bill. CBO priced each satellite at $22 million with a five-year life, sized the fleet to engage a raid of 10 ICBMs launched nearly at once in boost phase, and said dropping that layer would cut the 20-year cost to $448 billion, at which point the design would no longer match the order’s call for space-based interceptors.

Those 7,800 orbiters are a budget office sketch, not a signed constellation. They still show the scale jump. GIS Arta pairs guns on a front. Golden Dome is trying to pair sensors and shooters across air, land, sea, and space, on clocks that compress toward boost phase.

What Happens When the Fire-Control Screen Floods?

Obering’s warning sits in that gap. A continental fire-control picture can hold hundreds of thousands of objects at different altitudes, he wrote, plus decoys, plus harmless traffic, plus the handful of tracks that will kill people if no one shoots. Operators still have finite interceptors, doctrine, and nerves. Automation is the only way he sees to cut that load. Adding models without engineering the last mile can raise it.

Guetlein has already described the operational ask in the same direction. Existing overseas batteries each bring their own radars and shooters. Bringing them home, he said, means erasing the seams between THAAD, Patriot, Aegis, and the air and sea layers so one picture can pick an effector, close fire control, and do damage assessment.

That all requires a bunch of artificial intelligence. So we have architected that in as the foundation. And then what we want to do is give the warfighter the ability to select how much automation is going to be in the process, from none to fully automated. Because as the fight starts to become exceptionally dynamic, we’re going to want to go further and further towards automation because it’s going to be progressing at a faster than at machine speed, faster than human speed.

Gen. Michael Guetlein, director of Golden Dome for America

A dial from none to full auto sounds like a crew-protection feature. It is also a bet that the models behind the most automated setting will still work when the satellite link dies, when a video feed is lying, and when the officer who owns the shot has to explain why that track, not the one beside it, got the interceptor. Public argument still treats Golden Dome as orbital guns and a giant invoice. The quieter failure is a screen no one can trust at the speed the shield is being asked to think.

Telling a warhead from a balloon in space is an old physics problem. Cheap decoys ride with heavy objects once there is no air to sort them. The new stack wants that call in milliseconds, then wants a weapon assigned, then wants a human still on the hook. That is a software problem wearing a missile-defense budget.

Four Conditions That Decide Whether the AI Helps

Obering spent his last uniformed years running an 8,500-person agency and a $10 billion-a-year missile-defense portfolio. At Booz Allen he has been pushing directed energy and now the battle-management layer. He says infusing AI is the slogan, not the job. He lists four engineering tests that decide whether the software shrinks the OODA loop (observe, orient, decide, act) or just paints more alerts on the glass.

FOUR ENGINEERING GATES FOR MISSILE-DEFENSE AI

  • The edge: Models have to run in space, at sea, and in an operator’s pocket when the network is gone, because cloud compute will not be sitting on the booster.
  • The defense: Open-source and imported models remain open to spoofing during live inference, including doctored video, so training has to include attacks before the system ships.
  • The answer: Officers accountable for a shot need repeatable, explainable outputs, which means many small models fused on purpose rather than one net asked to swallow video, radio, and maps.
  • The clock: Wartime software in Ukraine has moved in days; U.S. model shops still burn years in test, unless they use simulated ranges to fail cheaply first.

No single vendor owns that stack, he argues, which is why Booz Allen talks about partners across mission and technology layers that used to sit in separate programs. The four tests are also a contractor’s product map. They still line up with the physics of a disconnected, spoofed, high-stakes fire-control loop.

Live Video Feeds Can Be Wiped in Real Time

Getting a vision model to high accuracy is not the end of the job, Obering wrote, because most open-source models sold into government still fail in inference. Booz Allen researchers took that claim to a conference floor. On April 27, 2026, Amol Khanna, a lead machine-learning scientist at the firm, presented work on real-time tampering of video object detectors at SPIE Defense and Security in National Harbor, Maryland.

The abstract describes a man-in-the-middle kit, written in Rust, that runs at more than 20 frames per second. One path is a digital invisibility cloak: it paints people out of a live feed by blending their pixels into a clean background. The other path uses pre-built universal adversarial perturbations to nudge the stream just enough that current detectors miss the objects. That is not a lab curiosity beside a missile-defense radar. If fire control trusts a video track, an attacker who owns the feed owns the shot list.

The other half of the trust problem is provenance. Obering said untrusted models, including tools built by the same states that might someday threaten U.S. airspace, are already showing up in government and critical infrastructure. The Navy told sailors in January 2025 not to use DeepSeek or other public open-source AI tools for official work, citing standing rules against commercial generative models on the job.

On September 8, 2026, CISA, NSA, and the FBI went further on the supply of those models. Their advisory said China-based firms, among them DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI, had run industrial-scale knowledge distillation campaigns against U.S. frontier systems, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. The agencies described billions of tokens pulled across millions of requests, likely with Chinese government awareness, as a shortcut around the cost of training.

A fire-control network that drinks from that well inherits the bias, the back door, and the attack surface. Obering’s fix is ugly and slow: expose models in training to adversarial examples until they hold up, then keep doing it after they deploy. Skipping that step is how a cheaper import becomes the thing an opponent already knows how to fool.

Neural Nets Drift; Missile Officers Need Repeatable Answers

Anomaly detectors that watch mass, acceleration, and deceleration can, in Obering’s telling, be aimed at particular classes of nuclear-capable objects. Decision-makers still need something else. They need outputs that are controlled at scale, mathematically repeatable, and explainable when a congressional office or a court-martial asks why that track died and the decoy beside it did not.

He argues a single net cannot stay repeatable once it is asked to fuse video, radio frequencies, and maps. The engineering pattern is many small models, each trained for one job, joined into one picture and one decision layer with a human still at the helm. A jungle detector is not a desert detector. A radar tracker is not a camera tracker. Glue them without saying which expert voted, and the officer gets a vibe instead of a reason.

Models also drift once they leave the lab. Dust, season, new paint on an airframe, a different seeker, a jammed GPS band: any of it can walk a net off its training distribution. Obering says they need constant retraining to stay inside bounds for reliability and availability. That is maintenance, not a launch-day miracle, and it has to be budgeted like propellant and spares.

Guetlein’s fully automated setting only makes that demand sharper. If the fight is moving faster than a person, the fusion layer is the weapon. If that layer cannot say what it saw, the dial is a coin flip with interceptors.

Digital Proving Grounds Still Have to Survive the Field

Ukraine’s software cycle, Obering wrote, has been measured in days in some cases. U.S. AI programs still get stuck in years of test and formal buying. His proposed shortcut is to put AI into the engineering process itself: digital ranges that replay weather, altitude, and failure modes at scale, so teams can break a design without flying a $22 million satellite into the Pacific.

The remaining risk is the sim-to-real gap. A pristine algorithm that only ever saw clean data will look brilliant in the petri dish and then fail on a dirty seeker. He says the same mix of models and sensors used in the lab has to be the mix used in the field, or the proving ground is a video game.

GOLDEN DOME’S PUBLIC CLOCK

  1. January 2025: The White House issues the Iron Dome for America order, later branded Golden Dome, calling for space interceptors and a layered homeland shield.
  2. April 2026: Space Force awards up to $3.2 billion in interceptor prototype work to 12 companies.
  3. May 12, 2026: CBO publishes its $1.2 trillion, 20-year sketch of a national system consistent with that order.
  4. August 11, 2026: Guetlein opens an industry hub in Huntsville, Alabama, as a single door for vendors into the program.
  5. 2026 to 2028: Ground tests, then orbital flights in 2027, then an on-orbit interceptor meant to plug into Golden Dome by 2028.
  6. 2035: Public planning still puts a full architecture here, a decade-class build even on a fast calendar.

That calendar is hardware. It does not, by itself, prove a fire-control model can run when the link drops, ignore a wiped video feed, and give a repeatable reason to the officer who still owns the shot. GIS Arta bought Ukraine minutes against massed guns. Golden Dome is buying orbiters and radars on a much larger clock. Unless the software clears those four tests, the extra shooters show up as extra alerts, and the crew is busier than before.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending