For four days in late June 2025, on a range at Fort Wainwright outside Fairbanks, Alaska, the Defense Innovation Unit flew prototype long-range attack drones against live jamming. The project, called Artemis, was meant to find cheap one-way attack aircraft that could reach a target through electronic attack. Defense News reported that one prototype repeatedly failed to find its target when jammed and ended the day in a hillside, and that another flew past its aim point and burned. Trent Emeneker, who led the project, told the outlet the results were “not what I would have hoped for.” He also said something more useful to anyone who writes test plans: without analyzing the data it was hard to know what had gone wrong, because the interplay of jamming and software bugs “gets complex.”

That admission is the starting point for a better way to judge autonomous systems. A flight in clear spectrum with good satellite navigation shows that the airframe and software function. It says very little about the property the military is paying for, which is the ability to keep doing something sensible after the link, the position fix or the mission assumptions have gone. Evaluation of autonomy should therefore be organized around dependencies and what the machine does when each is removed, including when it stops and when it asks a human for help. The Pentagon’s own policy already points in this direction. Its test capacity, its ranges and its reporting to Congress do not.

Ukraine’s fixes swapped one dependency for another

The war in Ukraine is usually cited as proof that autonomy works. Read closely, the evidence is narrower. In a February 2025 study for the Royal United Services Institute, Jack Watling and Nick Reynolds wrote that “between 60 and 80% of Ukrainian FPVs fail to reach their target,” and that navigational jamming was “ubiquitous throughout the combat area.” Both armies answered by removing the radio link. Drones that unspool a fiber-optic cable cannot be jammed, but the same RUSI paper recorded what operators gave up in early models: degraded flight performance, a range of roughly 10 kilometers and the risk of snagging the cable. Ranges have since grown. A February 2026 Atlantic Council assessment put Russian models beyond 30 kilometers and Ukrainian ones near 40, and said Ukraine had approved more than 80 domestic fiber-optic designs by mid-2025. In August 2026 Ukraine’s defense ministry announced its first purchase of fiber-optic strike drones to a common specification, a sign that the workaround has become a standard item.

The second answer was onboard terminal guidance, in which the operator designates a target and software flies the last stretch if the link drops. Kateryna Bondar’s March 2025 study for the Center for Strategic and International Studies reported hit rates of around 70 to 80 percent for drones with autonomous navigation against 10 to 20 percent under manual control. The same study is blunt about scope: autonomy in Ukraine is “partial,” improving particular functions while people still make engagement decisions. The limits show up in practitioner accounts. In a May 2026 report on interceptor drones, one manufacturer said its airframes built since March 2026 carry terminal guidance as standard, and a Ukrainian instructor observed that in cloud “even a computer struggles.”

Neither adaptation made the drone independent. Fiber traded a spectrum dependency for a physical one. Terminal guidance traded a link dependency for reliance on visibility and on a target that a human picked before the link failed. Ukrainian units learned those boundaries through losses, at a rate of iteration no peacetime force can copy. A peacetime force has to learn them in testing, which requires knowing in advance what each system leans on.

The policy asks a question the test enterprise struggles to answer

The governing U.S. document is DoD Directive 3000.09, reissued on January 25, 2023. Its text requires that autonomous and semi-autonomous weapon systems “function as anticipated in realistic operational environments against adaptive adversaries taking realistic and practicable countermeasures.” It also sets out a fallback rule. Systems must complete engagements within a timeframe and geographic area consistent with the commander’s intent, and if unable to do so must “terminate the engagement or obtain additional operator input before continuing.” That is a requirement about behavior at the edge of the envelope, written into policy almost four years ago. As the Congressional Research Service notes in its primer on the directive, the definitions turn on the role of the human operator in target selection and engagement, so navigation, sensing and other functions that fail first under jamming receive less formal attention than the decision to fire.

Test guidance has caught up on paper. The Developmental Test and Evaluation of Autonomous Systems Guidebook, issued in September 2025 by the office of the Under Secretary of Defense for Research and Engineering, warns that autonomous systems “often rely on datalink information, which can be disrupted, denied, or deceived,” and uses as its example an aircraft designed around GPS for a low-intensity conflict that is later needed in a GPS-denied one. The harder problem is where and by whom such testing gets done. After the Alaska trial, DIU officials told Defense News that most military ranges lack electronic warfare equipment and that disrupting GPS or communications in the United States requires approvals involving the Federal Aviation Administration and the Federal Communications Commission. A month before that trial, Defense Secretary Pete Hegseth ordered the office of the Director, Operational Test and Evaluation cut from 94 personnel to 46.

Satellite navigation deserves particular candor. On October 7, 2026, the Government Accountability Office reported that the department is still years from fielding jam-resistant M-code GPS receivers after more than two decades and billions of dollars, and that full fielding across Army aviation platforms is not expected until 2049. It also found the services’ alternative navigation efforts fragmented across numerous program offices. For anyone specifying an uncrewed system today, degraded GPS is the baseline condition for the life of the platform.

The money is moving ahead of the evidence

Replicator, announced in August 2023, set out to field thousands of attritable autonomous systems by August 2025. The Congressional Research Service records that the target was missed, citing a former official who said only hundreds had been fielded by then; a former Replicator director gave a similar account in September 2025, adding that thousands more were on contract. The effort was folded into the Defense Autonomous Warfare Group, and in December 2025 the head of Indo-Pacific Command described it as “very much alive.”

The fiscal 2027 budget then requested $54.6 billion for the group, against $225.9 million the year before, with $53.6 billion of it dependent on a reconciliation bill. Pentagon officials said in April 2026 that the group was “live right now, testing different systems” with companies. What those tests show is not public. In September 2026 the group’s director, Lt. Gen. Steven Marks, said its systems remain classified and warned that momentum would wane without funding; Breaking Defense judged passage of the reconciliation bill increasingly unlikely. Secrecy about capability is defensible. It leaves appropriators weighing a request of this size without any structured account of how the systems behave when denied, and the Congressional Research Service lists the adequacy of information available for oversight among the open issues.

What an evaluation record should contain

The remedy starts with paperwork that program offices can produce now. Every autonomous system offered for fielding should carry a dependency record that lists each external input it relies on, from satellite navigation and datalinks to prior maps and operator designation, and states the tested behavior when each is degraded, spoofed or absent. For each case the record should say whether the system continues, loiters, returns, hands off to a human or terminates, and how long it waits before choosing. Directive 3000.09 already demands the last two behaviors for engagements. Extending the same discipline to navigation and communications would close the gap the Alaska trial exposed, where a failure occurred and the cause could not be named on the day.

Test design should then invert its default. Denied conditions ought to be the standard run, with clean-spectrum flights treated as the control case, and that requires at least one standing range with permanent authority to jam navigation and communications signals so that vendors can iterate with operators present, as DIU officials asked for in 2025. Congress has leverage here. Whatever portion of the Defense Autonomous Warfare Group request survives, lawmakers could condition it on a classified annex reporting degraded-condition results by system, and could ask whether an operational test office at half its former size is able to check them. A vendor video of a swarm completing its mission proves the best case. Commanders deciding whether to trust a system need the record of its worst ones.

TaggedPentagonUkraineCongressDefense Innovation UnitDefense Autonomous Warfare GroupDirective 3000.09Replicator

This analysis draws on the public sources linked in the text. Send corrections to [email protected].

More in AI & Autonomy