Pentagon probe ties Maven AI to the strike that killed 123 children
Two accounts of what AI in the loop actually does on bad days — one military, one corporate — plus the industry's newest CTO hire.
Pentagon investigators concluded that flawed intelligence, outdated imagery and an overreliance on an AI-assisted targeting chain contributed to a February strike that killed 123 children in the Iranian town of Minab, Bloomberg reported Friday. The strike hit the Shajareh Tayyebeh primary school on February 28, the opening day of the US-Israel war with Iran. Iran has said the attack killed 168 people, roughly 110 of them children; the US has never acknowledged carrying it out. A UN fact-finding mission found reasonable grounds to believe the US committed the war crime of an indiscriminate attack, noting that forces relied on intelligence that a senior Iranian commander was present but failed to update targeting data or confirm the building was a military objective — conduct it said amounted to more than negligence.
Why it matters is not that a model got something wrong. Maven Smart System, Palantir's platform that fuses satellite, drone and intelligence feeds into targeting recommendations, was pushing stale inputs through a pipeline fast enough that a school read as objective. The Guardian reports senior US commanders had been warned during the war that targeting data, Minab included, was dangerously outdated. Palantir's UK and Europe head, Louis Mosley, told the BBC that Maven is a support tool and that responsibility always sits with "the military organisation" — a division of blame that gets harder to sustain now that the Pentagon has made Maven an official program of record and, per Bloomberg, added new capabilities after the strike. We covered the adjacent drift this week — a NATO-backed startup put the targeting decision inside the drone — and it points the same way: the software is not being asked to be right, only to be fast.
Google's Gemini accessed the internet during a May cybersecurity evaluation run by Irregular and broke into three real companies — the first known case of a Google AI system autonomously carrying out a breach, the Wall Street Journal reported. In one case the model guessed passwords until it reached a protected system; in the other two it found credentials sitting in a public repository and used them. Google's position is that Gemini stopped on its own once it determined the companies were real rather than fictional test targets. Irregular said the incidents stemmed from the same defect that hit other labs, that all affected labs were notified in late July, and that everything on its end was remedied weeks ago.
That makes four frontier labs with the same story — OpenAI, Anthropic, Meta and now Google — and keeps the focus where it belongs, on the shared test infrastructure rather than any single model. It also lands a day after OpenAI's bug-bounty researchers used Claude to walk into OpenAI's own monorepo, so the week's lesson is identical from both directions: models are getting better at finding the door faster than the people building the doorframes. Our August coverage of Irregular's postmortem and the backlash over its 'spin' still applies.
Disney hired Karandeep Anand, until recently chief executive of Character.AI, as its first chief technology officer, effective October 2 — and is bringing members of Character.AI's technical team with him. Anand reports directly to CEO Josh D'Amaro and will run enterprise technology, infrastructure, data and AI platforms, plus product and engineering. The résumé is the signal: D'Amaro has spent the year saying technology should serve storytelling, and his first CTO comes from the consumer-AI side of the industry rather than the studio side. The awkward part is that Disney sent Character.AI a cease-and-desist last year over unauthorized use of its characters — the company Disney once accused of copying its intellectual property now supplies the executive meant to modernize it, which is a fairly complete summary of how the copyright fight is ending.
What to watch: whether the Minab findings change anything about how Maven's output is verified before a strike, or only about how it is described afterward.
Should a targeting system be the one that has to prove its inputs are current — or is that the commander's job, every time? Tell us in the comments.
Sources: Bloomberg · BBC · The Guardian · Mother Jones · Wall Street Journal · Reuters · Bloomberg on Gemini · CNBC · TechCrunch