TEL AVIV, Israel (AP) — U.S. tech giants have quietly empowered Israel to track and kill many more alleged militants more quickly in Gaza and Lebanon through a sharp spike in artificial intelligence and computing services. But the number of civilians killed has also soared, fueling fears that these tools are contributing to the deaths of innocent people.
Militaries have for years hired private companies to build custom autonomous weapons. However, Israel’s recent wars mark a leading instance in which commercial AI models made in the United States have been used in active warfare, despite concerns that they were not originally developed to help decide who lives and who dies.
The Israeli military uses AI to sift through vast troves of intelligence, intercepted communications and surveillance to find suspicious speech or behavior and learn the movements of its enemies. After a deadly surprise attack by Hamas militants on Oct. 7, 2023, its use of Microsoft and OpenAI technology skyrocketed, an Associated Press investigation found. The investigation also revealed new details of how AI systems select targets and ways they can go wrong, including faulty data or flawed algorithms. It was based on internal documents, data and exclusive interviews with current and former Israeli officials and company employees.
“This is the first confirmation we have gotten that commercial AI models are directly being used in warfare,” said Heidy Khlaaf, chief AI scientist at the AI Now Institute and former senior safety engineer at OpenAI. “The implications are enormous for the role of tech in enabling this type of unethical and unlawful warfare going forward.”
The rise of AI
As U.S. tech titans ascend to prominent roles under President Donald Trump, the AP’s findings raise questions about Silicon Valley’s role in the future of automated warfare. Microsoft expects its partnership with the Israeli military to grow, and what happens with Israel may help determine the use of these emerging technologies around the world.
The Israeli military’s usage of Microsoft and OpenAI artificial intelligence spiked last March to nearly 200 times higher than before the week leading up to the Oct. 7 attack, the AP found in reviewing internal company information. The amount of data it stored on Microsoft servers doubled between that time and July 2024 to more than 13.6 petabytes — roughly 350 times the digital memory needed to store every book in the Library of Congress. Usage of Microsoft’s huge banks of computer servers by the military also rose by almost two-thirds in the first two months of the war alone.
Israel’s goal after the attack that killed about 1,200 people and took over 250 hostages was to eradicate Hamas, and its military has called AI a “game changer” in yielding targets more swiftly. Since the war started, more than 50,000 people have died in Gaza and Lebanon and nearly 70% of the buildings in Gaza have been devastated, according to health ministries in Gaza and Lebanon.
The AP’s investigation drew on interviews with six current and former members of the Israeli army, including three reserve intelligence officers. Most spoke on condition of anonymity because they were not authorized to discuss sensitive military operations.
The AP also interviewed 14 current and former employees inside Microsoft, OpenAI, Google and Amazon, most of whom also spoke anonymously for fear of retribution. Journalists reviewed internal company data and documents, including one detailing the terms of a $133 million contract between Microsoft and Israel’s Ministry of Defense.
The Israeli military says its analysts use AI-enabled systems to help identify targets but independently examine them together with high-ranking officers to meet international law, weighing the military advantage against the collateral damage. A senior Israeli intelligence official authorized to speak to the AP said lawful military targets may include combatants fighting against Israel, wherever they are, and buildings used by militants. Officials insist that even when AI plays a role, there are always several layers of humans in the loop.
“These AI tools make the intelligence process more accurate and more effective,” said an Israeli military statement to the AP. “They make more targets faster, but not at the expense of accuracy, and many times in this war they’ve been able to minimize civilian casualties.”
The Israeli military declined to answer detailed written questions from the AP about its use of commercial AI products from American tech companies.
Microsoft declined to comment for this story and did not respond to a detailed list of written questions about cloud and AI services provided to the Israeli military. In a statement on its website, the company says it is committed “to champion the positive role of technology across the globe.” In its 40-page Responsible AI Transparency Report for 2024, Microsoft pledges to manage the risks of AI throughout development “to reduce the risk of harm,” and does not mention its lucrative military contracts.
Advanced AI models are provided through OpenAI, the maker of ChatGPT, through Microsoft’s Azure cloud platform, where they are purchased by the Israeli military, the documents and data show. Microsoft has been OpenAI’s largest investor. OpenAI said it does not have a partnership with Israel’s military, and its usage policies say its customers should not use its products to develop weapons, destroy property or harm people. About a year ago, however, OpenAI changed its terms of use from barring military use to allowing for “national security use cases that align with our mission.”
The human toll of AI
It’s extremely hard to identify when AI systems enable errors because they are used with so many other forms of intelligence, including human intelligence, sources said. But together they can lead to wrongful deaths.
In November 2023, Hoda Hijazi was fleeing with her three young daughters and her mother from clashes between Israel and Hamas ally Hezbollah on the Lebanese border when their car was bombed.
Before they left, the adults told the girls to play in front of the house so that Israeli drones would know they were traveling with children. The women and girls drove alongside Hijazi’s uncle, Samir Ayoub, a journalist with a leftist radio station, who was caravanning in his own car. They heard the frenetic buzz of a drone very low overhead.
Soon, an airstrike hit the car Hijazi was driving. It careened down a slope and burst into flames. Ayoub managed to pull Hijazi out, but her mother — Ayoub’s sister — and the three girls — Rimas, 14, Taline, 12, and Liane, 10 — were dead.
Before they left their home, Hijazi recalled, one of the girls had insisted on taking pictures of the cats in the garden “because maybe we won’t see them again.”
In the end, she said, “the cats survived and the girls are gone.”
Video footage from a security camera at a convenience store shortly before the strike showed the Hijazi family in a Hyundai SUV, with the mother and one of the girls loading jugs of water. The family says the video proves Israeli drones should have seen the women and children.
The day after the family was hit, the Israeli military released video of the strike along with a package of similar videos and photos. A statement released with the images said Israeli fighter jets had “struck just over 450 Hamas targets.” The AP’s visual analysis matched the road and other geographical features in the Israeli military video to satellite imagery of the location where the three girls died, 1 mile (1.7 kilometers) from the store.
An Israeli intelligence officer told the AP that AI has been used to help pinpoint all targets in the past three years. In this case, AI likely pinpointed a residence, and other intelligence gathering could have placed a person there. At some point, the car left the residence.
Humans in the target room would have decided to strike. The error could have happened at any point, he said: Previous faulty information could have flagged the wrong residence, or they could have hit the wrong vehicle.
The AP also saw a message from a second source with knowledge of that airstrike who confirmed it was a mistake, but didn’t elaborate.
A spokesperson for the Israeli military denied that AI systems were used during the airstrike itself, but refused to answer whether AI helped select the target or whether it was wrong. The military told the AP that officials examined the incident and expressed “sorrow for the outcome.”
How it works
Microsoft and the San Francisco-based startup OpenAI are among a legion of U.S. tech firms that have supported Israel’s wars in recent years.
Google and Amazon provide cloud computing and AI services to the Israeli military under “Project Nimbus,” a $1.2 billion contract signed in 2021 when Israel first tested out its in-house AI-powered targeting systems. The military has used Cisco and Dell server farms or data centers. Red Hat, an independent IBM subsidiary, also has provided cloud computing technologies to the Israeli military, and Palantir Technologies, a Microsoft partner in U.S. defense contracts, has a “strategic partnership” providing AI systems to help Israel’s war efforts.
Google said it is committed to responsibly developing and deploying AI “that protects people, promotes global growth, and supports national security.” Dell provided a statement saying the company commits to the highest standards in working with public and private organizations globally, including in Israel. Red Hat spokesperson Allison Showalter said the company is proud of its global customers, who comply with Red Hat’s terms to adhere to applicable laws and regulations.
Palantir, Cisco and Oracle did not respond to requests for comment. Amazon declined to comment.
The Israeli military uses Microsoft Azure to compile information gathered through mass surveillance, which it transcribes and translates, including phone calls, texts and audio messages, according to an Israeli intelligence officer who works with the systems. That data can then be cross-checked with Israel’s in-house targeting systems and vice versa.
He said he relies on Azure to quickly search for terms and patterns within massive text troves, such as finding conversations between two people within a 50-page document. Azure also can find people giving directions to one another in the text, which can then be cross-referenced with the military’s own AI systems to pinpoint locations.
The Microsoft data AP reviewed shows that since the Oct. 7 attack, the Israeli military has made heavy use of transcription and translation tools and OpenAI models, although it does not detail which. Typically, AI models that transcribe and translate perform best in English. OpenAI has acknowledged that its popular AI-powered translation model Whisper, which can transcribe and translate into multiple languages including Arabic, can make up text that no one said, including adding racial commentary and violent rhetoric.
“Should we be basing these decisions on things that the model could be making up?” said Joshua Kroll, an assistant professor of computer science at the Naval Postgraduate School in Monterey, California, who spoke to the AP in his personal capacity, not reflecting the views of the U.S. government.