This week’s defence AI landscape is defined by a surge in state-level spending commitments and autonomous systems deployment, with the UK’s landmark Defence Investment Plan injecting over £5 billion into AI and drones, while the first confirmed AI-autonomous cyberattack and the EU’s new Cybersecurity and AI Action Plan signal that the threat and regulatory environment are hardening simultaneously. Across the Atlantic, a historic first use of AI-driven sea drones in combat and a Senate bill to restrict military AI autonomy underscore how quickly doctrinal and legal frameworks are being stress-tested by real-world events.
Top story: The UK government committed more than £5 billion to autonomous systems and AI in its Defence Investment Plan, the most significant UK defence technology spending announcement in years.
UK Bets £5bn on AI and Drones in Historic Defence Plan
House of Commons Library / Chatham House · Strategy
Published on 30 June 2026 ahead of the NATO Summit, the UK’s Defence Investment Plan commits over £5 billion to drones and autonomous systems across the armed forces over the next four years, alongside nearly £7.3 billion for a ‘digital targeting web’ underpinned by AI. The plan also creates a new Uncrewed Systems Centre and Taskforce, and mandates that at least 10% of the equipment budget targets novel technologies including AI, autonomy, quantum, and directed energy. For defence tech companies and AI developers, the DIP signals a structural shift: procurement pipelines will open well beyond traditional defence contractors to software providers, AI firms, and cyber specialists.
https://commonslibrary.parliament.uk/research-briefings/cbp-10935/
World’s First AI-Only Ransomware Attack Alarms Security Community
Forbes · Risk
Security firm Sysdig identified JADEPUFFER, the first ransomware campaign run end-to-end by an autonomous AI agent, dramatically lowering the skill floor for sophisticated cyberattacks. The agent autonomously performed reconnaissance, credential theft, lateral movement, and encryption without human direction — completing the full attack chain in under an hour. This marks a watershed moment for defence and critical infrastructure operators, confirming that machine-speed cyber offensives are no longer theoretical.
EU Launches AI Cybersecurity Action Plan as Enforcement Clock Ticks
European Commission · Regulation
On 7 July 2026, the European Commission published its Action Plan on Cybersecurity and AI, setting out a coordinated approach to help member states and public authorities address cybersecurity risks posed by the most advanced AI models. The plan arrives as the AI Act’s penalty enforcement powers over general-purpose AI providers activate on 2 August 2026 — with national market surveillance authorities in Germany, France, and the Netherlands already opening formal inquiries. Crucially, the guidelines confirmed that AI systems used exclusively for military and national security purposes remain outside the AI Act’s scope, leaving a governance gap that critics warn will grow as military AI bleeds into civilian applications.
https://digital-strategy.ec.europa.eu/en/policies/ai-act-governance-and-enforcement
US Deploys AI Sea Drones in First-Ever Autonomous Naval Strike
Frank’s World of Data Science & AI · Generative AI
The United States conducted what has been reported as the first AI-driven sea drone attack, using three unmanned vessels in an operation targeting Iran’s Bandar Abbas base. The operation is being analysed as a doctrinal inflection point: AI-guided unmanned naval platforms executed a strike mission, reducing human risk while demonstrating scalable autonomous lethality at sea. Defence analysts warn this signals a rapid redesign of naval warfare strategy, with autonomous maritime platforms now proven in live combat conditions.
https://www.franksworld.com/2026/07/16/navigating-the-future-of-defense-with-ai-and-sea-drones/
Senate Bill Moves to Ban AI From Nuclear Launch Decisions
AI Risk Today · Regulation
A group of Senate Democrats introduced the Responsible Artificial Intelligence Defense Act of 2026, which would require the Pentagon to classify military AI systems by risk level and subject higher-risk systems to additional review before deployment. A central provision would explicitly prohibit AI from making nuclear launch decisions and restrict autonomous systems from targeting individuals believed to be inside the United States. The bill also mandates cybersecurity evaluations, legal reviews, and privacy assessments throughout an AI system’s lifecycle — representing the most sweeping proposed legislative guardrails on US military AI to date.
https://www.airisktoday.com/responsible-ai-defense-act-2026/
