Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Saturday, September 26, 2026

Jus in Bello in the Digital Domain - When Code Becomes a Combatant

This post may be read in continuation with  the previous posts 'The Jus ad Bellum Dilemma' and 'The Resilience of International Law in the Digital Domain'

The previous posts examined the breakdown of jus ad bellum - the right to resort to force - in digital and cognitive theatres. Even if the ad bellum dilemma is solved and it is established that a cyber operation amounts to an armed attack under Article 51, a more intractable problem remains: jus in bello - how the laws of war are to be fought. 

Jus in bello which was codified in the Geneva Conventions and Additional Protocol I, rests on three non-negotiable pillars: Distinction, Proportionality, and Military Necessity. These principles assume a physical battlefield, a uniformed combatant, and a kinetic weapon. The digital domain dissolves all three.

1. The Crisis of Distinction

Article 48 of Additional Protocol I requires parties to distinguish at all times between civilian and military objectives and to direct operations only against military objectives.

A kinetic missile can be guided to a radar station. A cyber weapon cannot.

Modern military networks ride on civilian infrastructure. The same fiber optic cable that carries a commander's order carries a hospital's ICU data. The same cloud server that hosts a logistics application hosts civilian banking data. The Stuxnet worm, while precisely engineered to target Siemens PLCs at Natanz, spread to over 100,000 computers globally, including in India, Indonesia and the US.

Consider a scenario: to degrade an adversary's air defense network, a state deploys malware that disables Windows-based command and control servers. That same Windows vulnerability exists in the civilian air traffic control system. If the malware escapes - as worms are designed to - and causes civilian aircraft to crash, has the attacker violated distinction?

In a hyper-connected state, almost everything is dual-use because the lines between civilian infrastructure and military capability have completely blurred. The Tallinn Manual 2.0 (Rule 92) attempts to address this by stating that cyber operations must not be directed against civilian objects, but it offers no technical test for dual-use infrastructure. Rule 92 of the Tallinn Manual 2.0 provides a legal standard, but it lacks a technical or operational architecture to handle ubiquitous dual-use infrastructure.

When the underlying protocols, routing infrastructure, data centers, and fiber-optic cables are shared by hospitals and military command centers alike, distinguishing between a civilian object and a military objective becomes nearly impossible in practice.

Cognitive warfare compounds this further. When an adversary uses AI-generated deepfakes and algorithmic amplification to incite communal violence, who is the combatant and who is the civilian? The bot is non-human, the server is in a third country, and the victim is the civilian population's psyche itself. The principle of distinction, which was meant to protect civilians from war, is inverted - the civilian mind becomes the battlefield. 

2. Proportionality in a Cascade Failure

Proportionality under Article 51(5)(b)[1] prohibits an attack which may be expected to cause incidental civilian damage excessive in relation to the concrete and direct military advantage anticipated.

In kinetic warfare, proportionality can be calculated: a 500 kg bomb on a munitions depot may damage 2 houses. In cyber warfare, damage is non-linear and cascading.

Disabling a power grid to neutralize a military base is a classic case. The direct military advantage is clear. But the indirect effects - hospitals losing power, water treatment plants failing, financial systems collapsing, winter deaths - may far exceed the initial advantage. Unlike a bomb, the full extent of a cyber effect is often incomprehensible at the time of launch because the attacker may not have a complete map or understanding of the adversary's interdependencies.

The "scale and effects" test we discussed for ad bellum thus becomes a trap for in bello. A commander who launches a proportionate operation by his own estimates may end up committing a disproportionate attack due to cascade effects he probably could not reasonably foresee. Does this impose an absolute duty to conduct a network mapping of civilian dependencies before any cyber operation? If so, it would render most offensive cyber operations legally impossible - which may be the intent of the law. The commander will weigh the risks against the benefits of the operation before giving the go-ahead. 

3. Military Necessity and the Lethal Autonomous Layer

The most dangerous evolution is the merging of cyber with Lethal Autonomous Weapon Systems (LAWS)[2].

Jus in bello assumes human judgment in the loop. A human can assess military necessity in real time and call off an attack. When AI systems are trained to autonomously find and patch vulnerabilities, or autonomously launch counter-strikes at machine speed (a concept known as active defense), the time for legal deliberation shrinks to milliseconds.

If an AI-driven defensive system, upon detecting an intrusion, autonomously disables the attacking server which happens to be located in a hospital in a neutral country, who is responsible for the violation of neutrality and proportionality? The coder? The commander who deployed it? The machine?

This is where jus ante bellum assumes importance. The legal obligation cannot start at the moment of attack. It must start in peacetime, in the design, testing, and training data of these systems. During the phase of a critical operation, the commander may find it extremely difficult to abort or cease leading to irreparable consequences.

Towards a Doctrine

The resilience of international law in the digital domain will require three adaptations:

a) A presumption of civilian status for data: Like the presumption under Article 50(1) that a person is civilian in case of doubt, we need a presumption that data and infrastructure are civilian unless proven to be making an effective contribution to military action. When a person holds dual occupations—such as being a part-time journalist, doctor, or teacher while also serving as a member of an armed group—it creates significant legal, ethical, and practical challenges. 

b) A duty of cyber-reconnaissance and containment: Before any offensive operation, a state must demonstrate it undertook all feasible measures to map civilian interdependencies and to build containment / kill-switches into the weapon, akin to the duty of precautions in attack under Article 57.

c) Meaningful Human Control as a legal requirement: For any cyber operation that may cause physical damage, death, or severe disruption to essential civilian services, meaningful human control over target selection and proportionality assessment must be retained. Full autonomy in such operations must be deemed inherently indiscriminate.

If democracies ignore in bello in the rush to win the ad bellum argument, they risk winning the legal right to respond but losing the moral legitimacy of how they respond.

The code may be a weapon, but the law must still see the human behind the screen and the human at the other end of it.

 

 

 



[1] Article 51(5)(b) of Additional Protocol I to the Geneva Conventions codifies the core international humanitarian law principle of proportionality, prohibiting attacks expected to cause incidental civilian harm that is excessive in relation to the anticipated military advantage. 

[2] Lethal autonomous weapons systems (LAWS) are military systems that use sensors and artificial intelligence algorithms to independently identify, select and engage targets without direct human intervention.

Jus in Bello in the Digital Domain - When Code Becomes a Combatant

This post may be read in continuation with  the previous posts 'The Jus ad Bellum Dilemma' and 'The Resilience of International ...