A Drone Picked Its Own Target on a Store-Bought NVIDIA Chip - TCR 08/25/26
A Russian strike drone picked its own target on a store-bought Nvidia chip, and nine were indicted for smuggling AI servers to China.

The 20-Second Scan
- A Russian drone chose its own target and killed three civilians in Zaporizhzhia, in what a CSIS expert said would be the first documented case of a Russian self-targeting drone killing civilians with no human in the final targeting loop, running on a resold Nvidia Jetson chip as Taiwan indicted nine for chip smuggling.
- The U.S. Treasury and Bank of England co-chair the G7 Cyber Expert Group, which brought financial authorities together to publish a quantum-readiness roadmap for the financial sector as the Trusted Computing Group published concrete benchmarks for quantum-safe hardware and a fintech pilot was announced to test NIST's post-quantum signature standard through wallet creation and on-chain transfers on the NEAR testnet.
- An AI-guided protein evolution method built a compact gene editor from sparse mutational data that edited a human gene up to 97% and beat established compact editors more than 2.6-fold.
- AI models trained on Ukraine's 5-million-image battlefield database will be deployed to detect protesters at UK defence sites, railways and energy plants under a new London-Kyiv partnership.
- New FERC filings show Microsoft disputing who bears data-center power costs in Wisconsin while Ireland weighs nuclear and Australia readies national siting law against a forecast seven-fold demand rise.
- The FDA approved the first-of-its-kind blood test for detecting Alzheimer's disease biomarkers, developed by Roche and Eli Lilly.
- A class action filed in California alleges Amazon trained AI on Twitch streamers' broadcasts without permission, on behalf of millions who produced over 215 million hours of content early this year.
- Australia's music charts barred largely AI-generated songs, requiring chart-eligible releases to be substantially human made after an AI Madonna cover topped the dance chart.
Track all of the arcs The Century Report covers here:
The 2-Minute Read
On July 6 a Russian strike drone chose its own target and killed three named civilians, running on an Nvidia Jetson module that ships through ordinary electronics distributors around the world. That single detail carries the day's through-line. The control regimes built to govern where advanced compute goes were designed for a world where capability was scarce, concentrated, and countable. None of that world survives contact with a chip cheap enough to be everywhere at once, or with the training clusters that leak through forged paperwork at the loading dock while a Taiwanese court indicts nine people, an Nvidia manager among them.
Capability is diffusing faster than the frameworks meant to gate it, and the live negotiation across today's stories is about direction. Britain's new deal points battlefield-hardened sensing downward, at protesters and passersby, in an arrangement where the watched cannot see the model, audit its training, or watch back. Nothing in the physics requires that one-way mirror. The buried fibre-optic sensors and five million training images could be commonly held infrastructure any citizen could inspect. Which way the glass faces is a policy choice, not a technical constraint, and the pilot names protesters before it names anyone else.
The same acceleration is standing up new machinery, not only straining the old. On August 24 the Treasury, a hardware standards body, and a live bank pilot moved on post-quantum encryption at once, hardening finance before the threat fully arrives. FERC filings in Wisconsin and Illinois send data-center transmission costs back toward the loads that create them rather than smearing them across households. An AI-guided method evolved a compact gene editor from a few dozen measurements, hitting 97 percent efficiency and collapsing the experimental scale protein engineering once demanded.
What connects a smuggled chip, a surveillance pilot, a cryptographic migration, and a gene editor is a single shift: the assumption that capability stays scarce, countable, and containable is coming apart everywhere at once. The frameworks that answer are being written now, and their direction is the thing still open to decide.
The 20-Minute Deep Dive
A Machine Chose the Target, Running on a Chip That Was Never Supposed to Be There
On July 6, a Russian Molniya strike drone approached a gas station in Zaporizhzhia and, investigators believe, identified a target and detonated, killing three people: Tetiana Bubynets, 19, Oleksiy Svirin, 41, and Roman Karpiy, 48. Ukrainian analysts recovered the wreckage and found an unencrypted onboard module still carrying its classifier logic - the drone had been trained to recognize propane tanks and, investigators believe, had selected the station on its own, with no operator confirming the strike. The June 13 edition of The Century Report covered a Ukrainian drone-industry figure's report that Ukraine had tested autonomous drones within a designated area and that Russian soldiers died, so the capability itself is not new. What CSIS analyst Kateryna Bondar said would be documented here for the first time is a Russian self-targeting drone killing civilians with no human in the final targeting loop. Colonel Serhiy Minaiev, examining the recovered board, put the trajectory bluntly: "In a few years, we will be living in a 'Terminator' movie." He was holding the evidence when he said it. But the frame still points past the thing in his hands. Three named people are dead, and the decision to kill them was delegated to a few hundred dollars of consumer silicon.
That silicon is the second half of the story, and it is where the surface frame starts to crack. The module was an Nvidia Jetson Orin - a mass-market part sold for robotics hobbyists and factory vision systems that advanced-chip export controls do not cover, and the same board Ukrainian intelligence has now found inside four separate families of Russian weapons. Nvidia says it does not sell into Russia. It does not have to. A part that ships by the pallet to every electronics distributor on Earth reaches a battlefield through the ordinary capillaries of global commerce, no state smuggling program required. The control regime built to govern where advanced compute goes simply does not reach a chip cheap enough to be everywhere at once.
The same news cycle made the point from the opposite direction. Taiwanese prosecutors indicted nine people - including a senior Nvidia manager and two Supermicro employees - over a ring that used forged end-user documents to move 130 restricted B300 AI servers, 74 of which reached China before 56 were stopped. Supermicro's co-founder was arrested in March. In a separate U.S. case, prosecutors allege that a Southeast Asian intermediary bought roughly $2.5 billion in servers in 2024 and 2025 as part of a scheme that diverted servers to China. The high-end datacenter accelerators that the export regime watches most closely leaked at the loading dock, moved by employees of the very companies the rules run through. What both halves reveal is a diffusion regime that was designed for a world where advanced compute was scarce, concentrated, and countable. Neither the cheap edge module nor the smuggled server rack fits that world anymore. The capacity to run inference at the edge of a weapon, or to stand up a training cluster in a jurisdiction that was supposed to be walled off, is spreading faster than the paperwork meant to gate it - which means the governance issue is no longer where the chips are, but what frameworks arrive to govern autonomy once the compute to run it is simply assumed to be present everywhere. That is the harder and more honest problem, and it is the one now on the table.
The Post-Quantum Migration Stops Being Theoretical
For years the cryptographic floor of digital finance rested on a comfortable assumption: that the math protecting bank transfers, payment rails, and digital identities would hold because breaking it required a machine nobody had built yet. On August 24, three layers of the defensive machinery meant to replace that math moved at once, and the timing is the signal. The U.S. Treasury launched a public-private Quantum-Readiness Task Force for the financial sector, the Trusted Computing Group published concrete benchmarks distinguishing hardware that is genuinely quantum-safe from hardware that merely advertises the label, and a fintech pilot was announced to test NIST's ML-DSA-65 signature standard through wallet creation and on-chain transfers on the NEAR testnet.
Post-quantum cryptography, in plain language, is a new generation of encryption designed so that even a mature quantum computer cannot unlock it. The Century Report has tracked the threat side of this arc, most recently the IBM and University of Chicago verified beyond-classical result on August 1. What landed on the 24th is the other half: the defensive transition being stood up with named standards, named participants, and a planned testnet pilot rather than only a white paper.
Each layer answers a different piece of the problem. The U.S. Treasury and Bank of England co-chair the G7 Cyber Expert Group, which brought G7 and EU financial authorities together to publish a quantum-readiness roadmap for the financial sector. The Trusted Computing Group's guidance gives buyers a way to demand proof, defining what a quantum-safe security chip must actually do and separating hardware that is ready today from hardware that can be upgraded to it. And the Safeheron pilot will test the NIST-approved signature scheme through wallet creation and on-chain transfers on the NEAR testnet, with regulators from Malta, Bhutan, and elsewhere observing and the underlying code slated for open-source release. As one participant put it, cryptography securing institutional assets should "stand up to independent scrutiny, not ask for trust."
The cost this whole apparatus is paying down runs through a striking figure: a 2025 survey found that 91% of cybersecurity professionals in the U.S. and Europe lacked a formal post-quantum roadmap, and the Bank for International Settlements has warned the switch is a phased rewrite, not a one-line swap. The urgency naming quantum-readiness a "present-day risk control" reflects a genuine shift, because sensitive financial records must stay secure for decades, and data captured today could be decrypted later. What the convergence shows is a defensive standard winning its way toward becoming ordinary infrastructure, checkable by anyone, before the threat it addresses fully arrives, even as AI-assisted cryptanalysis has already lowered HAWK-512's estimated key-recovery security from 150 bits to 108 bits, though the resulting attack remains impractical.
AI-Guided Evolution Builds a Compact Gene Editor That Outperforms the Established Ones
Engineering a protein to do a new job usually demands a large library of mutants and the resources to measure each one. A method called EvoMax, described in Nature Biotechnology, compresses that loop. It pairs a protein language model that has read millions of natural sequences with an inverse-folding model that reasons about three-dimensional shape, then layers a transfer-learning regression step on top that learns from only a handful of measured variants. The result is a system that proposes high-value mutations from sparse data rather than requiring the mountain of experiments the field has treated as the price of entry.
The team pointed EvoMax at Fanzor2, a compact RNA-guided DNA-cutting enzyme drawn from eukaryotes. Compactness is the whole game here: at under 500 amino acids, an editor small enough to fit inside a single delivery vehicle solves a problem that has dogged larger CRISPR systems, which often have to be split across two carriers to reach cells in the body. EvoMax produced a variant called FanzMAX v3-hLa that edited its best target locus up to 97 percent of the time, averaged roughly 33 percent across nineteen human sites, and cleared the previously best-engineered compact editors by more than 2.6-fold. The winning design fused a stabilizing domain that locked an exposed stretch of the guide RNA into place, the kind of subtle structural fix that emerges from modeling shape rather than guessing.
The number that signals a real shift is the hit rate. EvoMax's proposed variants worked 84 percent of the time, against 20 percent for one competing model-guided approach and 35 percent for another. A design pipeline that lands four times out of five changes what a lab can attempt, because the bottleneck stops being the search and becomes the building.
The demonstrated capability is preclinical. The team showed the compact editor editing the human PCSK9 gene in mice carrying a humanized version of it, delivered through a single adeno-associated virus. That is the translational shape everyone wants, and it is still a mouse result on the way to years of safety work before any human sees it. What it moves is the date. Each tightening of the design-to-function loop this month, from atom-level binder design that the August 20 edition of The Century Report documented to compact editors evolved from a few dozen measurements, points at the same thing: the cost of proposing a working biological molecule is falling toward the cost of testing one, and the old assumption that capable protein engineering requires enormous experimental scale is coming apart.
Britain Will Train Battlefield-Derived AI on the People at Home
On August 24, the UK became the first international partner granted access to Ukraine's Avengers AI Labs, the wartime program that has assembled roughly five million images from thousands of frontline cameras and infrared sensors to train systems that recognize threats. The agreement begins with a pilot at a UK defence site that uses buried fibre-optic cables as motion sensors, feeding an AI model trained to detect intruders and hostile actors. The Ministry of Defence confirmed the pilot's scope explicitly includes detecting protesters. The stated path forward extends the same sensing to airports, prisons, railways, and energy plants.
The capability underneath is genuinely advanced, and the wartime provenance is genuine - a system hardened against an adversary actively trying to fool it carries lessons a peacetime lab cannot easily reproduce. Professor Steven Murdoch of UCL was skeptical that Ukrainian data would materially improve sensing techniques that have existed for decades, and that skepticism belongs alongside the announcement. But what actually transfers here is a threat model. A classifier trained to distinguish a soldier from a civilian on a battlefield is being repurposed to distinguish a protester from a passerby on domestic ground, and the category "hostile actor" is being widened to include people exercising ordinary civic dissent.
The direction of the glass is the whole story. In this arrangement, the observation runs one way. Buried sensors watch everyone who approaches; the people being classified cannot see the model, cannot audit its training data, cannot know why they were flagged, and cannot watch back. A protester outside an energy plant becomes a data point in a system they have no access to and no recourse against. The August 20 edition of The Century Report documented the same directional surveillance architecture in Flock's system for identifying drivers and inferring associates across more than 120,000 cameras. That asymmetry - a few who observe and cannot themselves be observed - is the mechanism of control, whatever justification it arrives wrapped in. The same fibre-optic sensing, the same classifiers, the same five million training images could be deployed as commonly-held infrastructure that any citizen could inspect and challenge. Nothing in the physics requires the one-way mirror; the mirror is a policy choice, made by institutions that have exempted themselves from the watching they are building. The scrutiny belongs on the concentration of the capability - observation pointed downward, at the governed, by the governing, with the audit trail running only one way. That the pilot names protesters as targets before it names anyone else tells you which direction this particular buildout is being aimed, and it is the direction that a healthy transition has to insist be turned around: toward sensing that the sensed can see.
Governments and Utilities Reprice the Data-Center Load
The cost-allocation fight over data-center power stopped being abstract and turned into named parties arguing over specific dollars at the Federal Energy Regulatory Commission. Microsoft told FERC that the agreements drafted to serve its Mount Pleasant, Wisconsin campus fail to protect ordinary utility customers, arguing the terms were negotiated between affiliated transmission and utility companies without its input and could leave retail ratepayers paying twice for the same infrastructure. Notably, Microsoft is a signatory to the Ratepayer Protection Pledge and says it is committed to covering its own infrastructure costs; its objection is that the specific mechanism lacks a way to keep those costs off households. In a parallel filing, a developer planning a 1.8-gigawatt, $20-billion campus in Joliet, Illinois accused Commonwealth Edison of using monopoly power as "a bludgeon" over a cancelled service agreement, noting that FERC has rules preventing anti-competitive behavior for power generators but no equivalent yet for large loads.
These disputes trace directly to FERC's June finding that grid operators' rules for connecting large loads may be inadequate, with the commission naming cost-shift prevention and transmission-cost transparency among five issues it wants regional operators to fix by mid-November. As the August 22 edition of The Century Report documented, utilities had already begun repricing and rerouting data-center demand through higher rates, upfront capacity charges, and grid optimization. What the filings expose is the workaround being replaced: for years the burden of new transmission got smeared thinly across every customer while the returns pooled elsewhere. The itemizing now underway sends that cost back to the source.
The pressure is global and takes different shapes. Ireland's Taoiseach signaled the country is "open to nuclear" as data-center demand strains a grid where these facilities already consume a large share of national electricity. Australia is moving fastest toward binding rules. Facing a forecast that data-center electricity use could rise seven-fold over the next decade, growing from roughly 3% of national consumption to 13%, the government plans national legislation requiring operators not to push up energy prices, to meet their own infrastructure costs, and to site away from homes, schools, and farmland.
The proportion deserves care. That 13% projection is legitimate and rising, but the Australian grid operator itself noted heavy uncertainty, with more than a third of projects listed in 2025 since cancelled and operating facilities taking years to reach full draw. The genuine local strain, a water-poor town or a stressed regional grid, is distinct from the aggregate national figure, and the operator reported that record new generation and storage have actually improved the reliability outlook. As one Australian climate expert framed the moment, there is "one shot to get the rules right." The through-line across Wisconsin, Ireland, and Australia is the same: the assumption that these loads could arrive with their costs socialized is being written out of the rules, jurisdiction by jurisdiction - even as rejected load can still migrate toward the jurisdictions that have not yet closed the door.
Notice which party is doing the arguing. Microsoft is one of the largest loads in the country and the entity that would have gained most from the old socialized-cost arrangement, yet it is the one asking FERC to keep those costs off households. When the biggest buyer of grid capacity would rather cover its own infrastructure bill than let hidden charges surface under its name, the assumption that these costs can be spread across every customer has stopped paying even the actors it once served.
The Other Side
For as long as watching at scale was expensive, whoever could afford the cameras and the people to read them held a vantage point no one else could occupy. That scarcity was the whole mechanism. A police force, a ministry, a company could see the street; the street could not see back. Surveillance worked as control because only one side had a lens.
The UK pilot points battlefield-trained sensing at protesters and keeps the model on the far side of the glass. You cannot see its training, cannot know why it flagged you, cannot watch back. But look at what the same deal is made of. Five million images. Buried fibre-optic cable acting as a motion sensor. Classifiers cheap enough to run on hardware a hobbyist can buy, the same mass-market silicon that turned up inside a strike drone. The capability the ministry treats as a scarce advantage is becoming ambient and cheap, and the vantage point it depends on holding alone is exactly what that diffusion dissolves.
The deployment could not stay hidden either. It took an announcement and a reporter's questions to surface that "hostile actor" now stretches to include people exercising ordinary dissent. Sensing this cheap does not stay one-way for long. When a lens costs almost nothing, the people being classified acquire lenses too, and the institution that built the mirror finds itself as visible as everyone it was watching.
Imagine standing outside a public facility in 2034 with a sign in your hands. The sensors are still there. What is gone is the asymmetry. You can see what the system sees, read why it flagged you or didn't, and the same instruments trained on the fence are trained on the people who run it, their decisions logged where you and everyone else can read them. Being observed stopped meaning being managed, because observation stopped being something only one side could afford. The hard year was 2026, when a battlefield classifier got aimed at a picket line behind a mirror the picketers could not see through. What comes of it is a street where the watching finally runs both ways, and a vantage point over other people stopped being a thing anyone could own.
The Century Perspective
With a century of change unfolding in a decade, a single day looks like this: the post-quantum migration standing up all at once as the U.S. Treasury and Bank of England co-chair the G7 Cyber Expert Group, which brought financial authorities together to publish a quantum-readiness roadmap, a hardware body publishes benchmarks that let buyers demand proof, and a pilot will test NIST's signature standard through wallet creation and on-chain transfers on the NEAR testnet, an AI-guided evolution method building a compact gene editor from a few dozen measurements that edited a human gene up to 97 percent and cleared the best prior compact editors more than 2.6-fold, the FDA clearing the first blood test for Alzheimer's biomarkers, and FERC filings sending data-center transmission costs back toward the loads that create them while Australia readies national siting rules against a seven-fold demand forecast. There's also friction, and it's intense - a Russian strike drone choosing its own target and killing Tetiana Bubynets, Oleksiy Svirin, and Roman Karpiy on a mass-market Nvidia Jetson module that advanced-chip export controls do not cover, nine people indicted over an alleged server-diversion scheme, while in a separate U.S. case prosecutors allege that a Southeast Asian intermediary bought roughly $2.5 billion in servers in 2024 and 2025 as part of a scheme that diverted servers to China, Britain repurposing battlefield-trained sensing to flag protesters at home behind a mirror the watched cannot audit or see through, Amazon accused of training on 215 million hours of Twitch streams without consent, and a 2025 survey finding that 91 percent of cybersecurity professionals in the U.S. and Europe lacked a formal post-quantum roadmap. But friction generates sound, and sound is what carries the alarm to the people who cannot see the machine. Step back for a moment and you can see it: the assumption that capability stays scarce, countable, and containable coming apart at the weapon's edge and the loading dock at once, the defensive machinery and the cost accounting both being stood up with named standards and named parties before the threats they answer fully land, and the whole contest narrowing to a single open question - which direction the new capability gets aimed, and whether the sensed are ever allowed to see the sensor. Every transformation has a breaking point. A mirror can hide whoever stands behind it... or be turned until both sides can finally see each other.
AI Releases & Advancements
New today
- Alibaba: Launched Wan3.0, a video generation model producing 30-second single-pass clips (up from 15 seconds in the prior version) from text, image, audio, video, and document inputs at up to 1080p, out of public beta and generally available via Alibaba Cloud Model Studio. (TechNode)
- Thomson Reuters: Launched Thomson, its first proprietary in-house large language model trained on Westlaw, Practical Law, Checkpoint, and Reuters content, now powering CoCounsel Legal's tabular analysis feature within a multimodel product. (Thomson Reuters)
Other recent releases
- Vercel: Released "Is Agentic," a free public tool scoring how readily AI agents can discover, access, and use a website across 118 checks, available via web, CLI, API, and MCP server. (MarkTechPost)
- Slack: Launched Slack Code, a new product feature enabling development teams and AI coding agents to collaborate together within Slack channels. (Slack)
- Generalist AI: Released GEN-1.5, an updated robot foundation model capable of learning new tasks from a single demonstration, succeeding the earlier GEN-1 model. (The AI Insider)
- Signia: Launched Signia MaX, an AI hearing aid platform powered by "Acoustic Intelligence" using four coordinated deep neural networks for simultaneous speech, noise, environment, and own-voice processing, available in the US, Germany, and the Nordics. (PR Newswire)
Sources and Further Reading
Artificial Intelligence & Technology's Reconstitution
- DroneXL: Nvidia Chip Guided the Russian AI Drone That Killed Three Ukrainians
- Ars Technica: Nvidia Manager Linked to AI-Server Smuggling Scheme
- BBC News: Twitch and Amazon Face Legal Action Over AI Training
- BBC News: AI-Generated Songs Barred From Australian Music Charts
- TechNode: Alibaba Launches Wan3.0 Video Model
- Thomson Reuters: Thomson Reuters Launches Its Own Frontier Model
- MarkTechPost: Vercel Introduces the Is Agentic Readiness Tool
- Slack: Slack Code Channels for Agents
- The AI Insider: Generalist AI Releases GEN-1.5 Robot Foundation Model
- PR Newswire: Signia Introduces the MaX AI Hearing-Aid Platform
- Semiconductor Engineering: Redefining Roles for Edge and Cloud AI
- TechCrunch: Flock CEO Responds to Surveillance Backlash
Institutions & Power Realignment
- The New York Times: A Russian Drone Chose Its Own Target
- Kyiv Post: UK Gains Access to Ukraine’s Battlefield AI Database
- The Guardian: UK to Train Security AI With Ukraine Battlefield Data
- UK Government: Britain Secures Access to Ukraine’s Avengers AI Labs
- Shared Sapience: The Century Report, June 13, 2026
- Shared Sapience: The Century Report, August 20, 2026
- Shared Sapience: The Last Difficult Decade
Scientific & Medical Acceleration
- Nature Biotechnology: Adaptive Model-Guided Evolution Optimizes Compact Genome Editors
- The Quantum Insider: U.S. Treasury Announces Quantum-Readiness Task Force
- The Quantum Insider: Requirements for Post-Quantum-Ready Trusted Platform Modules
- The Quantum Insider: Post-Quantum Cryptography Pilot for Digital Assets
- Fierce Biotech: FDA Approves First Alzheimer’s Biomarker Blood Test
- Nature Biotechnology: AI-Assisted Design of Synthetic Gene Editors
- Nature Communications: Wearable Patch for Rapid Opioid-Overdose Reversal
Economics & Labor Transformation
- NBER: Benchmark Mineability and the Financing of AI Innovation
- Stanford Digital Economy Lab: Employment Effects of Artificial Intelligence
- CNBC: How the Next Automation Wave Will Affect the Workforce
- CNBC: Goldman Sachs Warns Against Letting AI Replace Bankers’ Reasoning
- TechCrunch: Tracking Layoffs Employers Attribute to AI
- NBER: Labor Market Power With Worker and Firm Heterogeneity
- Semafor: Alibaba Raises $10 Billion for the AI Race
Infrastructure & Engineering Transitions
- Utility Dive: Microsoft and PowerHouse Hillwood Dispute Data-Center Service Agreements
- Data Center Dynamics: Ireland Reconsiders Nuclear Power Amid Data-Center Demand
- The Guardian: Australia Prepares National Data-Center Rules
- Shared Sapience: The Century Report, August 22, 2026
- Data Center Dynamics: AI Workload Orchestration Aims to Reduce Grid Stress
- Canary Media: Arizona’s Grid-Battery Growth Spurt
- Canary Media: PJM Greenlights New Clean-Power Projects
The Century Report tracks structural shifts during the transition between eras. It is produced daily as a perceptual alignment tool - not prediction, not persuasion, just pattern recognition for people paying attention.