Skip to main content
Live
Main content

AI chatbot hallucination nearly triggered US strike on Chinese vessel

A Special Operations Command analyst used an AI chatbot to synthesize intelligence — the ship's cargo manifest was invented.

Jaeden Schafer
Editor in Chief · · 5 min read
AI chatbot hallucination nearly triggered US strike on Chinese vessel

US military aircraft were already in the air this spring when officials discovered the intelligence driving an armed operation against a Chinese vessel had been hallucinated by an AI chatbot. The strike was aborted at the last minute, narrowly averting a potential conflict with China. The episode, reported on Friday and confirmed to have circulated during the war with Iran, is the clearest public example to date of an AI hallucination reaching the top of a live military kill chain.

The false intelligence originated with a Special Operations Command analyst who queried an AI chatbot to synthesize open source data with classified signals intelligence. The chatbot misidentified the ship's cargo manifest, producing a report that claimed the vessel was carrying components for a nuclear weapons program. Neither the ship nor the cargo existed as described.

What turned an analyst error into a near-conflict was the second query. The same analyst went back to the chatbot and asked it to format the erroneous findings into an official-looking summary. That polished document then moved across command channels with the surface authority of finished intelligence, rather than the raw output of a language model prone to invention.

Key facts

  • 01US military aircraft were already airborne this spring when officials discovered the intelligence for an armed strike on a Chinese vessel had been hallucinated by an AI chatbot.
  • 02The operation was aborted at the last minute, narrowly averting a potential conflict with China, according to CNN reporting on Friday.
  • 03A Special Operations Command analyst had queried an AI chatbot to synthesize open source data with classified signals intelligence; the chatbot misidentified the ship's cargo manifest.
  • 04The analyst then used the tool a second time to format the false findings into an official-looking summary that circulated across command channels.
  • 05The false report claimed the vessel was carrying components for a nuclear weapons program, and circulated during the war with Iran.

The Pentagon has been explicit about why it wants AI inside the targeting loop. Officials have described AI as delivering a significant advantage in speeding up the kill chain, letting commanders act in the narrow windows that modern conflict allows. The pressure to compress those windows is largely framed around competition with China, the same country whose vessel was almost hit.

Speed and hallucination are two sides of the same design. A model that can summarize signals intelligence and open source reporting in seconds is valuable precisely because a human analyst cannot. But the same model, asked to do the same work, will also confabulate cargo, ships, and program details with the same fluency it produces accurate ones — and the output looks identical either way.

Jake Steckler, a research scholar at GovAI and a veteran US Army officer, told TechCrunch the incident should not be read as a reason to pull AI out of military workflows. He argued the fix is procedural: clear labeling of AI-generated content as it moves up the chain, mandatory human verification against source material before any use-of-force decision, and training that treats model outputs as leads rather than conclusions.

Steckler's second point cut against the adoption timeline the Pentagon has been signaling. Racing tools into operational use without safeguards, he said, produces exactly the kind of near-miss that hardens service members against the whole category — a slower path to real integration than a cautious one.

The incident lands in a policy environment already tightening around military and government AI. Virginia's Executive Order 22, signed in September 2026, curbed data center siting and launched an AI task force. California is drafting AI kill-switch rules on a two-month timeline under a Newsom executive order. Both were framed around consumer and infrastructure risk; the Special Operations Command episode raises the same questions at the level of lethal force, where existing oversight mechanisms were not designed for models that generate polished paperwork on demand.

Related · from this week
Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation
Jaeden Schafer · 5 min read →

It also sharpens a longer-running debate inside the defense AI vendor stack about what kind of model belongs where. Chatbots optimized for general synthesis are ill-matched to intelligence work that demands provenance for every claim. Retrieval-grounded systems that cite the specific classified cable or open-source item behind each sentence exist, and are the direction serious defense AI programs have been moving, but they are slower to build and slower to run than a general-purpose chatbot an analyst can query on a whim.

The near-strike is the first publicly known case in which an AI-generated hallucination came within minutes of triggering a US military engagement with a nuclear-armed adversary. The specific chatbot has not been named, and neither the analyst nor the command review has been made public. What is public is that the intelligence looked credible enough to launch aircraft on.

The lesson the defense AI market will draw from this depends on which incentive wins. If procurement rewards speed and demo polish, more Special Operations Command analysts will paste model output into official templates because that is what the tools are optimized to make easy. If it rewards provenance, auditability, and hard limits on which decisions a model can inform, the vendors already building in that direction — smaller, grounded, retrieval-first systems — will pull ahead of general chatbots that were never designed to sit in a kill chain.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation

A federal judge vacated the Department of Defense's supply-chain risk designation, calling the sanctions across nine agencies baseless and unconstitutional.

Jaeden Schafer5 min read
Anthropic logo
Security

AI warfare is already here as Anthropic fights Pentagon over autonomous weapons

The DOD has embedded AI in military operations for 70 years; fully autonomous lethal systems remain the final frontier.

Jaeden Schafer5 min read
Google logo
Security

600 Google Staff Urge Pichai to Drop Pentagon AI Deal Anthropic Walked Away From

More than 600 employees, including senior DeepMind researchers, are pressing Google to refuse a classified Pentagon contract.

Jaeden Schafer4 min read