Israel’s Wolfpack System: A Case Study Marking the Collapse of Surveillance and Targeting in AI Warfare
Natalie Kim
Volume 2 • Issue 2
Introduction
It goes uncontested that artificial intelligence has rapidly become a fixture of modern warfare. From AI loitering munitions in the Artsakh War to autonomous reconnaissance drones in the ongoing Ukraine–Russia conflict, the past sixteen years have witnessed a staggering evolution of AI applications in geopolitical conflict. But a less visible – and more alarming – shift is now underway. Rather than operating as isolated tools, AI systems are being wielded in tandem with one another, feeding data between programs to create a new type of warfare entirely. In this new landscape, civilians and their data are being preeminently surveilled in the name of apartheid and political unrest. This marks a critical departure from the war we know: AI is now being used to push the battlefront into civilians’ digital footprints, homes, and faces, while feeding into the same systems that control airstrikes.

Fig. 1. Surveillance cameras sighted in 2022 mounted in the Old City of Jerusalem. (Anne Paq/Activestills)
Nowhere is this shift clearer than in a newly reported AI database, the IDF’s Wolfpack system currently in use within the Israel–Palestine war. An overarching surveillance network built from three constituent applications – Blue Wolf, Red Wolf, and White Wolf – Wolfpack leverages facial recognition, smartphones, and CCTV cameras to wage this new form of war on Palestinians within the West Bank and East Jerusalem. Wolfpack marks a structural shift in what warfare is and who it touches — where surveillance, policing, and targeting no longer operate as separate functions but as a single, self-expanding system, and one that severely violates human rights and autonomy.
This report aims to analyze the mechanics of the Wolfpack system, how its multi–head system marks a new age of AI in warfare, and why this shift is alarming for questions in privacy and autonomy.
Section I: What is Wolfpack?
“
If function creep is near-inevitable once a database like Wolfpack exists, then the harms documented here are not a worst-case scenario. They can expand to be inflicted more severely, on more minority groups, in less time.
While the Israeli military has not officially acknowledged the existence of the Wolfpack system, various reports in the past decade have confirmed it as an AI–powered database of information on upwards of the 350,000 Palestinians who live in the West Bank and East Jerusalem (Grote, 1). Many of the most recent of these reports agree that the moniker ‘Wolfpack’ refers to the overarching database, containing information as sensitive as Palestinians’ “permits, family members, license plates, and whether they are wanted by the Israeli authorities” (Amnesty, 41). Its three branch applications, Blue Wolf, Red Wolf, and White Wolf, are used in the field to collect more data in real time. This data then flows back into the central Wolfpack, continually expanding the database and its surveillance network.
First reported with Blue Wolf’s deployment in 2016 and consolidated into the broader Wolfpack system by 2019–2021, Wolfpack has been swift to evolve into coordinated collaboration between its three spokes and the central hub. Reports from the Washington Post in 2021 note that before the whole picture was put together, Palestinians would be detained from the street to slowly collect data through direct human communication: “They would effectively hold a detained person in front of the CCTV camera, and then the operations room would pull information from the Wolf Pack system. That’s an old system that requires this link-up between the operations room and the soldier on the ground, and it’s since been upgraded” (Robins-Early).
Now, Blue Wolf, Red Wolf, and White Wolf are reported to have distinct functions which have retired the prior model of soldiers communicating with the operations room. Blue Wolf is the name of a mobile smartphone app used by Israeli soldiers, which uses AI facial recognition to identify Palestinians in real time. The app is ‘gamified’ in format, reported to reward soldiers or units who scanned and recorded the ID’s of the most Palestinians with benefits such as extra breaks. According to testimonies from Israeli veterans via activist organization ‘Breaking the Silence’, Blue Wolf is run on a separate phone each soldier has: “It’s just a phone that only has this program on it, it just has a camera and this program” (Breaking the Silence).

Fig. 2. An Israeli soldier uses Wolfpack in 2025 to photograph a Palestinian civilian during a raid in the occupied West Bank. (Avishay Mohar/Activestills)
Red Wolf is another spoke of the Wolfpack hub, and is a program that uses the same facial recognition technology as Blue Wolf at physical checkpoints Palestinians cross in and out of every day. The cameras at each checkpoint, of which there are reported to be as many as twenty-four, take pictures of Palestinian passerby without their knowledge or consent so their biometric data can be entered into Wolfpack (Amnesty, 44). If their biometric ID is already in the Wolfpack system, a red, yellow, or green flash at a Red Wolf checkpoint indicates if that Palestinian may cross through to the other side (red: arrest, yellow: detain, green: pass). These checkpoints are stationed at places of work, education, healthcare, and family residences.
White Wolf, the third reported branch of Wolfpack, is offered to Israeli settlers as a limited access mobile app to the Wolfpack database, giving settlers the ability to identify the Palestinians nearest to them. Much less is known about White Wolf in comparison to Blue and Red Wolf. Some sources dispute if White Wolf is an alternate name for the overarching Wolfpack database, or if it is a separate application on its own (Dincer), (Seibt). However, more recent reports seem to support White Wolf as a separate branch that feeds into Wolfpack similarly to Red Wolf and Blue Wolf.
The biometric facial recognition technology and data transmission networks that feed into Wolfpack are powered by AI-compatible CCTV cameras. Human rights organization Amnesty International and news publication the Middle East Eye have identified these devices as being sourced from manufacturers like Chinese tech company Hikvision and TKH Security in the Netherlands. These cameras never turn off, and are operational 24 hours a day for seven days a week (MEE Staff, 1). According to their manufacturers, these cameras employ deep learning capability to continually absorb more “simultaneous detection of persons [and] faces” (Amnesty International, 62).
Together, Blue, Red, and White Wolf enable a constant and oppressive surveillance of Palestinians, extracting more than just their names or identity. Their faces, their families, homes, places of work, and known affiliates are all data fed back into the Wolfpack, owned by the IDF, who assumedly use this information for militant purposes. As AI engineer and security researcher Baris Dincer notes, “ together, these systems create a closed-loop identity intelligence cycle. This architecture enables persistent surveillance and near-instantaneous identity resolution… far more dangerous than it appears: data collection (Blue Wolf), data storage and enrichment (Wolfpack/White Wolf), and real time enforcement and access control (Red Wolf)” (Dincer).
Section II: Key Differences Between AI in War Before, and Wolfpack
It is necessary to first establish the existing types of AI systems in warfare in order to understand how Wolfpack is an alarming departure – and collapse – of these domains. As outlined by sources including the International Committee of the Red Cross, the Brennan Center for Justice, and others, AI applications in war typically fall into one of three main categories: 1) surveillance and reconnaissance systems, which aggregate biometric and digital
footprints, 2) advanced targeting suites, and 3) Lethal Autonomous Weapons Systems (LAWS), which execute physical strikes without human intervention (ICRC, Brennan Center for Justice).
There exist examples from different geopolitical conflicts across the globes of AI systems in each category. An application known as ‘Lavender’ is a system that falls in the first category: surveillance and reconnaissance, and is actively being wielded in the Israel–Palestine conflict since 2023. Developed by the Israeli Defense Forces, Lavender uses AI machine learning to generate Palestinian targets for assassination, and has been reported to be used on any Palestinian that is suspected of being a Hamas operative. The system learns what the IDF considers to be indicative ‘characteristics’ of hostile operatives and parses for these features in Palestinian population data. Such characteristics include being in a Whatsapp group with a confirmed militant, changing mobile devices frequently, or home addresses frequently. It assigns suspected operatives a risk score, and if this score is high enough, the target is immediately assumed an automatic target (Iraqi, 6). The kill lists generated by Lavender have been used to drive mass bombings of Palestinians despite no confirmation of their accuracy, and in fact are described to be treated as ‘if they were human decisions’ (Iraqi, 1). Other instances of AI surveillance include systems like Wolfpack, as well as tracking tools like “Where’s Daddy?”, which coordinate bomb strikes based on data collected directly from Palestinian smartphone locations (Iraqi, 2). More broadly, AI-assisted ISR (intelligence, surveillance, reconnaissance) technology has been expanding in armed conflict since 2012, seen in Russia’s deployment of Orlan reconnaissance drones in Ukraine in 2014, and culminating in modern “hyperwars” where AI fuses satellite imagery, live drone feeds, SIGINT, missile telemetry, and cyber intelligence into unified real-time networks (Linn, 2).
The second category, advanced targeting, can be seen in AI systems developed by the U.S. military. Maven, a program developed by American tech giant Palantir, is able to generate the advised fuel, munitions, and coordinations of a given target from pools of data within seconds to a maximum of a few minutes. Recently leveraged in Operation Epic Fury, a U.S.
AI-supported coalition strike against Iranian targets, Maven’s rapid decision–making algorithm enabled the killing of over 13,000 targets within the first 40 days of the Iran war (Sidhu, 1). With only one layer of human approval, Maven exemplifies the lowered human presence in advanced AI targeting systems. Powered by Wide Area Motion Imagery drones, RQ-180 stealth reconnaissance drones, Raptor drones that do not need GPS, and more, Maven is considered one of the deadliest targeting systems ever created. Historically, AI targeting and planning systems trace back to the Pentagon’s DART Project during the 1990 Gulf War, a DARPA-backed application used to schedule and mobilize military supplies and personnel (Military Embedded Systems, 1). Over the past decade, advanced targeting has evolved into projects like the 2020 Artsakh War, where Azerbaijan paired the AI navigation of Bayraktar TB2 drones with the high-value target hunting of Israeli Harop munitions to strike Armenian troops (Harutyunyan).
Lastly, the acronym LAWS (for Lethal Autonomous Weapons Systems) describes a third category of AI in war: AI combative systems or algorithms that do not require any human intervention to operate. A prominent documented instance of LAWS is the STM Kargu–2 drones used in the 2020 Libyan Civil War. As reported by the UN, the STM Kargu–2 drones were programmed to attack fire on targets with zero connectivity to any human operator, and were only neutralized via jamming of the electronic system Koral they ran on (United Nations, 17). LAWS designs have rapidly expanded in the past decade, evidenced by the use of loitering munitions—or “kamikaze” drones—which patrol target areas before autonomously diving to strike. First popularized by Iranian Shahed-136s in 2018, these systems are now deployed on a massive scale. In the Russia-Ukraine conflict—often called the first true “AI war” (Linn, 2)—Russia fields similarly autonomous platforms like the V2U drone, which uses onboard software to engage targets without human intervention.
These three categories: surveillance, targeting, and LAWS, are larger umbrellas for the many AI systems used by militant bodies throughout the globe.
Wolfpack differs alarmingly from other AI applications in these categories because it represents a conceptual collapse between category 1 (surveillance) and category 2 (targeting). Embedded directly into physical infrastructure—checkpoints, street corners, and soldier smartphones—it turns routine acts like walking to school or passing through a turnstile into automated inputs for military classification. Through its interconnected web of Red, Blue, and White Wolf, the system does not passively collect data to be analyzed later; it prompts immediate hostile action towards Palestinians deemed ‘threats’. The second a checkpoint camera or soldier app scans a face and assigns a color-coded threat level, the user is no longer merely being “surveilled.” They are actively being categorized for potential neutralization. When a surveillance network produces an immediate operational outcome—locking a turnstile, alerting armed patrols, or updating a threat score in a central database—it ceases to be passive monitoring. And this is only what has been reported from soldier testimonies and activist reporting missions. It is suspected Wolfpack data has been used to feed larger IDF bombings and similarly multiple–fatality missions on top of detaining Palestinians in civilian centers.
Additionally, Wolfpack’s Blue, Red, and White Wolf constituents communicate and feed into one another, and into the central database, in a way that no prior standalone system was structured to do. Unlike other reconnaissance systems like Lavender, which is wielded at will for
specific strikes by the IDF, Wolfpack is constantly collecting data and limiting Palestinian freedom and privacy. Wolfpack is not applied at specific times or in specific situations – it is active 24/7, creating profiles for every Palestinian it encounters. The data it collects on Palestinians’ faces, occupations, family residences, smartphone activity, age, citizenship, and more, can be fed into any of the above aforementioned targeting or LAWS applications – demonstrating a flexibility no other systems possess.
As the framing goes, these cross-collaborative systems are changing what warfare even is, dissolving any boundaries between surveillance and killing. Rather than operating as an on–demand tool, Wolfpack—a mass biometric network deployed across checkpoints and streets—is an ever–expanding database that constantly collects information for potential feeding into any targeting, LAWS, or other actionable platform.
Section III: Why We Must Worry About Wolfpack’s Difference
A primary concern regarding Wolfpack lies in how its departure from strictly surveillance or strictly targeting normalizes the gradual, unchecked weaponization of civilian infrastructure. A 2021 report from the human rights organization Privacy International warns that the Israeli military’s biometric facial recognition technology already violates privacy and ethics concerns by “monitor[ing] marginal and minority groups” (Palestinians) — which, alarmingly, can “eventually [extend] to the majority” (Weitzberg, 8). The report goes on to state that “the case of Israel/Palestine speaks to these broader dangers of technological function creep.”
The notion of “function creep” – most thoroughly explored in literature by technology scholar Bert-Jaap Koops – gives voice to the precise ethical dangers and implications Wolfpack poses. Koops describes function creep as the process where a technology’s application gradually widens beyond its original purpose, and in a policing context, where “a government’s
programme of technological intervention into social life is gradually, incrementally, but deliberately increased over time…when personal data, collected and used for one purpose…migrate to other ones that intensify surveillance and privacy invasions beyond what was originally understood” (Koops, 1).
Wolfpack is this function creep happening in real time. Standard CCTV cameras, originally intended as recording instruments, have been weaponized into selective biometric tools that continuously feed sensitive civilian data from specific minority groups directly into active military targeting systems. As Koops emphasizes, function creep is inherently dangerous because it snowballs: once a surveillance database expands beyond its initial scope, it establishes the groundwork for a permanent, inescapable surveillance state. In a wartime context, this expansion is particularly deadly. The fact that commercial surveillance infrastructure can be so easily warped into an automated, targeted threat matrix proves that current human tragedies are doing nothing to deter bad actors from advancing—and expanding—these technologies.
Another cause for concern is Wolfpack’s emphasis on data collection shifting fundamental human roles in war: even what it means to be a soldier. Breaking the Silence testimonies from former IDF sergeants show that foot soldiers are no longer deployed for on-the-ground warfare or missions alone; soldiers instead are changing from human militants into reconnaissance vessels, so their mobile devices can collect Palestinian data. In the 2020 testimony ‘The point was to take photos’, a former sergeant states “Blue Wolf …I honestly think this replaced [mapping missions]. Instead of writing down ‘here lives X, Y, and Z’, you simply have photos” (Breaking the Silence). Gone are the days of mapping missions with on–the–ground troops. Foot soldiers have become prongs in the field, deployed to widen population surveillance as much as to fight.
Perhaps unsurprisingly, the Israeli military claims any recognition systems or AI technology they may wield is for greater ‘security purposes’ – but the function creep of warfare AI reciprocally bleeding into surveillance AI reveals the dangers of coverups such as these. This technology may seem passive in its data aggregation day–in and day–out, but the pressure of its implications is crushing. Palestinians’ faces, their neighbor’s faces, their jobs, families, and health reports, are being used to aid the war effort against Gaza: a toll paid in hundreds of thousands of lives.
This convergence is rising in other AI systems, too. Networks also used by the IDF, Lavender and Where’s Daddy, pool data on civilians’ residences, places of work, building structures, and smartphone activity to make killing more efficient (Harutyunyan).
Another critical concern is that the Wolfpack system, despite its use at every major checkpoint and intake of hundreds of Palestinians’ IDs daily, is demonstrably unreliable. Further Breaking the Silence testimonies reveal that Israeli soldiers who used Blue Wolf were themselves aware the system was inaccurate in identifying Palestinians, with one soldier describing it as “very beta” and noting that “it also didn’t work that well” (Breaking the Silence). These inaccuracies carry real consequences: many Palestinians have been unjustly detained based on flawed facial recognition results, with one Israeli officer telling the Times in 2024 that the technology has falsely tagged civilians as militants, a mistake that likely culminated in their intake, potential questioning, or worse (Robins-Early). Others have been barred from returning to their own communities or homes simply because the system failed to recognize them.
These failures are compounded by ‘automation bias’, a term that describes the human tendency to defer to an algorithm’s decision without considerable critical judgment. As described by military AI author and political science professor Elke Schwarz, people are especially prone to automation bias by “ignor[ing], or not [searching] for, contradictory information in light of a computer-generated solution…when lethal decisions are at stake, automation bias risks the loss of situational awareness” (Schwarz, 64).
But the nuanced truth is, automation bias is not the only factor likely influencing the perpetuation of Wolfpack throughout the West Bank. Soldiers and other military personnel may be forcibly pressured or intimidated via rank into deferring to the algorithm, regardless of their own judgment. This is automation bias played out on an institutional level, or what scholars call ‘AI-washing.’ AI-washing occurs when governments force compliance to an algorithm at the operational level, which simultaneously absolves any one individual of moral accountability—casting responsibility for harmful outcomes into the ambiguous void between human command and the machine (Robins-Early).
Wolfpack’s function creep between surveillance on civilians to actionable wartime data, its consistent use despite reported inconsistencies, and alarming perpetuation of systemic automation bias are on their own accord each major causes for concern for the future of AI in warfare. Together, they present an urgent case of violations in human privacy, standard warfare practice, and the role of technology in government.
Section IV: Conclusion and Future Research
Wolfpack’s cross-collaborative architecture, its role in normalizing mass biometric collection, and its documented unreliability point to something larger than a flawed piece of military technology. If function creep is, as Koops suggests, near-inevitable once a database like Wolfpack exists, then the harms documented throughout this essay are not a worst-case scenario. They can expand to be inflicted more severely, on more minority groups, in less time.
This raises questions that extend well beyond Wolfpack itself, and that future research will need to grapple with. If AI-enabled surveillance and targeting systems are already embedded in active warfare, one urgent need is for continued investigative journalism and independent research into the mechanics of these overlapping systems, particularly as the conflict continues and as Wolfpack’s constituent parts likely continue to evolve in ways not yet publicly documented.
This essay raises a harder, more uncomfortable question about the broader project of AI development itself: does striving to improve facial recognition and related technologies, even outside of war contexts, increase the likelihood that these tools will eventually be appropriated by bad actors for nefarious purposes? Put differently, can a balance be achieved in working to make AI more accurate and more capable while preventing this technology from falling into the wrong hands? And is this even possible, with the unfortunate reality that is the power of funding and monetary incentives across military, software, and political bodies?
Wolfpack’s presence suggests that hostile bodies will continue to refine any AI machine that more efficiently services political agendas, however violent they may be — concurrently, future AI warfare research must take seriously a fundamental truth: automated surveillance and targeted tools, once created, will in all likelihood creep toward systemic misuse. We are no longer observing the evolution of military technology, but contending with an era where AI is fundamentally redefining the nature of warfare itself.
Works Cited
10946, and 10172. “The Military’s Use of AI, Explained.” Brennan Center for Justice, 11 Mar.
2026, www.brennancenter.org/our-work/research-reports/militarys-use-ai-explained.
Accessed 20 July 2026.
Amnesty International. Automated Apartheid: How Facial Recognition Fragments, Segregates, and Controls Palestinians in the OPT. Amnesty International, 2023, www.amnesty.org/en/documents/mde15/6701/2023/en/.
Breaking the Silence. “Testimony 280983.” Breaking the Silence, www.breakingthesilence.org.il/testimonies/database/280983.
Dincer, Baris. “Israel’s Wolf Pack Surveillance System.” Medium, April 18, 2026, medium.com/@brsdncr/israels-wolf-pack-surveillance-system-2167a4987c89.
“Frequently Asked Questions: Artificial Intelligence (AI) in the Military Domain.” International Committee of the Red Cross, 11 June 2026,
www.icrc.org/en/article/faq-artificial-intelligence-in-military-domain. Accessed 20 July 2026.
Grote, Tatjana. “Wolfpack Surveillance System in the Occupied Palestinian Territories (Since 2021).” Cyber Law Toolkit, CCDCOE, https://cyberlaw.ccdcoe.org/wiki/Wolfpack_surveillance_system_in_the_occupied_Palestinian_territories_(since_2021).
Harutyunyan, T. “AI Technologies in Recent Wars and Armed Conflicts (2010–2026).” Arvak, 25 May 2026,
https://arvak.am/en/ai-technologies-in-recent-wars-and-armed-conflicts-2010-2026/.
Iraqi, Amjad. “‘Lavender’: The AI Machine Directing Israel’s Bombing Spree in Gaza.” +972 Magazine, 3 Apr. 2024.
Koops, Bert-Jaap. “The Concept of Function Creep.” Law, Innovation and Technology, vol. 13, no. 1, 2021, pp. 29–56. DOI.org (Crossref), doi:https://doi.org/10.1080/17579961.2021.1898299.
Linn, Thomas C. “Research & Debate: The First AI War.” Naval War College Review, vol. 79, no. 2, 2026, pp. 1–10.
MEE Staff. “Wolf Pack: Israel’s Accelerated Use of Facial Recognition ‘Automated Apartheid.’”
Middle East Eye, 2023,
https://www.middleeasteye.net/news/wolf-pack-israel-accelerated-use-facial-recognition-automated-apartheid.
Military Embedded Systems. “Artificial Intelligence Timeline.” Military Embedded Systems, https://militaryembedded.com/ai/machine-learning/artificial-intelligence-timeline.
Robins-Early, Nick. “How Israel Uses Facial-Recognition Systems in Gaza and Beyond.” The Guardian, 19 Apr. 2024,
www.theguardian.com/technology/2024/apr/19/idf-facial-recognition-surveillance-palesti nians.
Schwarz, Elke. “Autonomous Weapons Systems, Artificial Intelligence, and the Problem of Meaningful Human Control.” Philosophical Journal of Conflict and Violence, vol. 5, no. 1, 2021, pp. 53–72.
Seibt. “How Israel Uses Facial Recognition Technology to Monitor West Bank Palestinians.”
France 24, 10 Nov. 2021,
https://www.france24.com/en/middle-east/20211110-how-israel-uses-facial-recognition-technology-to-monitor-west-bank-palestinians.
Sidhu, Bilawal. “Inside Palantir’s Maven Smart System.” Map the World, Substack, 30 Apr.
2026.
United Nations, Security Council. Letter Dated 8 March 2021 from the Panel of Experts on Libya Established Pursuant to Resolution 1973 (2011) Addressed to the President of the Security Council. S/2021/229, 8 Mar. 2021, undocs.org/S/2021/229.
Weitzberg, Keren. Biometrics and Counter-Terrorism: Case Study of Israel/Palestine. Privacy International, May 2021,
https://privacyinternational.org/sites/default/files/2021-06/PI%20Counterterrorism%20and%20Biometrics%20Report%20Israel_Palestine%20v7.pdf.

