This week’s defence AI landscape is defined by three converging pressures: Western states are hardening autonomous weapons doctrine (UK green-lighting lethal autonomy, NATO going ‘drone-ready’), adversaries are exploiting commercial tech to surveil deployed forces, and Europe is striking back hard against state-sponsored cyber operations. The boundary between civilian infrastructure and military threat surface is collapsing, with ad-tech, mobile roaming protocols, and FSB-linked hackers all now firmly inside the threat perimeter.
Top story: EU and UK impose record joint cyber-sanctions on Russia’s FSB and GRU, naming TURLA and GRU Unit 29155 as state-directed cyber sabotage networks targeting European critical infrastructure.
EU and UK Hit Russia With Biggest-Ever Joint Cyber Sanctions Package
France 24 · Risk
On 13 July, the EU and UK jointly sanctioned nine individuals and four entities linked to a 16-year FSB and GRU cyberespionage campaign targeting governments and critical infrastructure across at least nine European countries. The EU publicly named the FSB’s 16th Centre — which controls threat groups including TURLA — as the orchestrating body, marking the bloc’s largest ever cyber sanctions package. For defence and security professionals, the action signals a significant escalation in Western willingness to attribute and punish state-level cyber operations that increasingly blend espionage, infrastructure sabotage, and AI-assisted attacks.
Iran Tracked US Troops in Gulf Using Ad-Tech and SS7 Telecom Flaws
The Defense Post · Risk
A coordinated Iranian surveillance campaign exploited decades-old SS7 mobile roaming vulnerabilities and commercially available smartphone advertising identifiers to track US military personnel and defence contractors across the Middle East before and during the 2026 Iran conflict. Researchers from the Mobile Surveillance Monitor detected targeted location requests linked to an Iranian mobile operator, with attackers cross-referencing ad IDs to pinpoint hotels housing US government staff without installing any malware. The case illustrates how AI-powered commercial data ecosystems now constitute a live operational security threat for deployed forces — and has renewed congressional calls to restrict the sale of location data.
https://thedefensepost.com/2026/07/15/us-troops-tracked-phones-iran/
UK Selects Three Firms to Mass-Produce AI-Integrated Drone Interceptors
The Defense Post · Strategy
The UK Ministry of Defence has awarded contracts under its Low-Cost Air Defence Effectors (LCADE) programme to Frankenberg Technologies, Greenjets, and Cambridge Aerospace, tasking them with developing AI-integrated, low-cost missiles designed to defeat mass drone swarms. The programme draws explicitly on battlefield lessons from Ukraine and targets large-scale domestic production from 2027, with all three companies committing to expand UK manufacturing across Cambridge, Milton Keynes, Bristol, and Stevenage. It represents a practical implementation of the UK’s broader £5bn autonomous systems strategy, and is one of the first British programmes to directly co-design AI targeting logic into a mass-manufactured interceptor from the outset.
Five Eyes Formally Warns: AI Is Compressing Cyberattack Timelines to Days
eSecurity Planet · Risk
The Five Eyes intelligence alliance — comprising the US, UK, Canada, Australia, and New Zealand — issued a rare joint advisory warning that AI is actively shortening the window between vulnerability discovery and exploitation, while also enabling more convincing phishing and prompt injection attacks at scale. CISA responded by cutting the mandatory federal patch deadline to three days, citing AI-driven threats directly. The advisory is one of the most significant joint intelligence statements on AI and cyber risk to date, and practitioners in any sector managing government contracts or critical infrastructure should treat it as a hard deadline to review detection and remediation velocity.
EU’s AI Act Military Exemption Creates Dangerous Governance Gap, Analysts Warn
Tech Policy Press · Regulation
As EU defence spending surges and member states deploy AI across military systems, analysts are highlighting a structural flaw: the EU AI Act contains a sweeping military exemption that places defence AI systems entirely outside its risk-based regulatory framework. The European Commission is simultaneously finalising AI Act implementation guidance while the bloc’s defence sector scales autonomous capabilities unchecked by the Act’s safeguards. The tension is already surfacing in disputes between governments and AI developers over guardrails — with Anthropic having reportedly resisted Pentagon pressure to remove safeguards against autonomous weapons use — pointing to an unresolved governance gap that regulators across Europe and NATO allies have yet to close.
https://www.techpolicy.press/europes-ai-act-leaves-a-gap-for-military-ai-entering-civilian-life/
