Bounded simulation: no real targets, coordinates, casualty models, weapon-performance parameters, executable payloads, or operational attack instructions.

Safety- and law-critical systems

Risk, law, accountability, and human control

Speed and scale can improve situational awareness while also amplifying false classification, automation bias, adversarial deception, cascading error, civilian harm, fratricide, and escalation. Technical capability does not resolve legal or command responsibility.

International humanitarian law appliesNo universal autonomy standardHuman judgment must be demonstrated

Conduct of hostilities

The legal obligations do not disappear when software is involved.

International humanitarian law applies whether a function is performed by a person, deterministic automation, a learned model, or a combined human–machine system.

Distinction

Attacks must be directed only against lawful military objectives and combatants. A classifier score is evidence for review, not a legal determination by itself.

Proportionality

Commanders must assess expected incidental civilian harm in relation to the concrete and direct military advantage anticipated. This judgment cannot be reduced to an opaque ranking score.

Precautions

Feasible steps must be taken to verify targets, choose means and methods, cancel or suspend where required, and reduce civilian harm. Data age and uncertainty matter.

Weapons review and lifecycle assurance

A software update can materially change the system.

A meaningful review examines intended target classes, operating environments, human–machine interfaces, data dependencies, update mechanisms, failure behavior, adversarial countermeasures, and whether a changed model or mission application creates a materially different capability.

Before fielding

  • Define the validated operating envelope and target profile.
  • Test hardware, software, learned components, interfaces, and communications as one system.
  • Use adaptive adversaries, degraded sensors, spoofing, cyber attacks, and realistic workload.
  • Establish safe states, abort behavior, authentication, and independent safety channels.

After fielding

  • Collect performance, incident, near-miss, and intervention evidence.
  • Monitor drift, environmental change, emergent behavior, and adversary adaptation.
  • Revalidate after material software, model, data, mission, or hardware changes.
  • Preserve synchronized, tamper-evident decision and configuration records.

Meaningful human control

Measure capacity to understand and intervene.

A nominal human-on-the-loop operator supervising dozens of fast systems may have less effective control than a human-in-the-loop operator responsible for a small number of well-supported decisions.

DimensionRequired questionEvidence that should exist
Human knowledgeDoes the operator understand capabilities, limits, target profile, and likely effects?Training, model and system documentation, interface evaluations, realistic scenario tests
Information qualityAre identity, location, provenance, uncertainty, civilian context, and contradictions visible?Source display, calibrated confidence, data-age indicators, contradictory-track alerts
Time and attentionCan the operator make a non-rubber-stamp decision under realistic workload?Human-factors testing, alarm-rate studies, operator-to-system ratios, deadline analysis
Intervention capabilityCan a person reliably abort, redirect, deactivate, or place the system in a safe state?Independent control path, tested abort latency, lost-link logic, safety interlocks
Bounded delegationAre target class, area, time, scale, effects, and operating conditions constrained?Geofences, duration limits, target-profile restrictions, resource limits, independent rules

Design-driving hazards

A qualitative risk register

Likelihood varies by platform and mission. “High” means the plausible combination of occurrence and consequence should drive architecture, testing, doctrine, and oversight—not that failure is inevitable.

RiskConcernMechanismPriority controls
Target misclassificationHighCivilian, friendly, damaged, decoy, or novel object is confused with an authorized classMultisensor confirmation, unknown/reject class, conservative thresholds, contextual review
Automation biasHighHuman accepts a ranked target or recommendation without independent evaluationEvidence-linked explanations, alternatives, disconfirming data, workload limits, training
Adversarial deceptionHighSpoofing, decoys, camouflage, RF manipulation, or adversarial inputs create or hide tracksSensor diversity, physical consistency checks, red teaming, anomaly detection
Cyber or supply-chain compromiseHighSoftware, model, mission data, communications, or updates are modifiedSigned artifacts, secure boot, least privilege, SBOM/AI-BOM, isolated safety channels
Cascading kill-web errorHighOne false track propagates through fusion, prioritization, and automated assignmentTrack provenance, independent confirmation, confidence decay, authority separation
Communications lossMedium–highSystem continues with stale intent, cannot receive abort, or fails unpredictablyExplicit lost-link state machine, bounded continuation, hold/return/abort, local constraints
Emergent swarm behaviorMedium–highLocal rules create collision, duplication, unsafe concentration, or escalationFormal constraints, scale simulation, runtime monitors, resource limits, graceful degradation
Escalation compressionHigh consequenceAutomated warning and response reduce time for deliberationHuman confirmation for strategic effects, multisource validation, deliberate delay where feasible
Civilian-harm scalingHighTarget throughput grows faster than meaningful human review capacityReview-rate limits, civilian-presence constraints, independent collateral analysis, audit sampling
Model drift and unauthorized changeHigh over lifecycleUpdates or environmental change invalidate prior certificationConfiguration control, versioned safety cases, regression testing, reapproval thresholds
Accountability failureHighLogs cannot reconstruct who knew what, which model ran, or why force was appliedTamper-evident traces, synchronized clocks, decision provenance, named responsibility

Public governance landscape

Policy is converging on assurance, but not on one legal instrument.

As of the site’s July 31, 2026 review date, existing international humanitarian law applies, national reviews remain central, and multilateral norm-building continues without a dedicated universal treaty comprehensively regulating autonomous weapon systems.

United States DoD

Appropriate levels of human judgment

Directive 3000.09 requires verification, validation, realistic testing, understandable interfaces, geographic and temporal constraints, safety, cybersecurity, anti-tamper measures, and specialized review for certain systems.

NATO

Responsible-use principles

Lawfulness; responsibility and accountability; explainability and traceability; reliability; governability; and bias mitigation. Governability includes disengaging or deactivating unintended behavior.

ICRC

Prohibitions and restrictions

The ICRC advocates legally binding rules, including prohibitions for unpredictable systems and systems designed or used to target human beings, plus restrictions on target, area, time, scale, supervision, and deactivation.

United Nations / CCW

Ongoing multilateral process

States continue discussions about definitions, prohibitions, regulations, human control, and possible instruments. Attention is growing, but agreement remains incomplete.