CyCon 2026 Series – New Technologies, Armed Conflict, and International Humanitarian Law
Editors’ note: This post introduces a series derived from panels and discussions that took place in 2026 at the 18th annual International Conference on Cyber Conflict (CyCon) event hosted by the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia. This year’s theme was “Securing Tomorrow.”
New technologies are changing how armed forces understand the battlefield and conduct operations. Artificial intelligence (AI) systems can sift through imagery, sensor feeds, and intelligence at great speed, while cyber capabilities are now woven into communications, logistics, targeting, and command. Use of these capabilities has raised a pressing question how established international humanitarian law (IHL) rules are applied when information moves faster, systems interact across domains, and military decisions depend increasingly on digital infrastructure. A system may identify patterns or suggest that a person or object resembles a lawful target, yet it cannot in every case determine on its own whether a person is surrendering, wounded or otherwise hors de combat; whether a civilian object has become a military objective; or whether circumstances have changed since the information was collected. These judgments required by IHL remain deeply dependent on context.
Nor can the concern be answered simply by keeping a human “in the loop.” Human involvement matters only if the decision-maker has enough time, information, understanding, and authority to examine what the system presents and to reject its recommendation where necessary. Confidence scores and technical accuracy may assist that process, but they cannot replace legal judgment or remove the uncertainty that has always shaped military operations. Where data are incomplete, outdated, biased, or deliberately manipulated, technology may give an incorrect conclusion an appearance of precision and make it harder to question. Reports concerning Lavender and Gospel in Gaza, and AI-assisted analysis estimated by some to have informed mistaken targeting of a school in Minab, illustrate how weaknesses in information and review can carry through an operation.
Compliance therefore must be built into a capability before deployment and maintained throughout its operational life. Procurement and development processes should preserve access to testing evidence, known limitations, update histories, and the documentation needed to audit, correct, suspend, or withdraw a system. Where a capability constitutes, or forms part of, a new weapon, means or method of warfare, an Article 36 review should examine it as it is expected to be used rather than assess the algorithm in isolation. That includes its data, interaction with human operators, foreseeable failure modes, tested operating environments, and vulnerability to cyber manipulation or deception. Updates, retraining and use in new settings may alter performance, so legal review requires clear triggers for reassessment rather than a single approval at acquisition. Clear procedures are needed to determine when a system must be tested and reviewed again, in other words, managing the system through life-cycle governance.
None of these safeguards will be effective unless IHL is understood and applied throughout the institutions responsible for developing, acquiring, and using new technologies. Legal rules cannot remain confined to specialist advice or appear only at the final stages of development and operational planning; they must inform decisions from the outset and remain relevant as technologies, circumstances and military practice evolve. This requires sustained cooperation across legal, operational, and technical communities, as well as a clear understanding of how established protections apply when activities and infrastructure increasingly span physical and digital environments. The contributions that follow take up these questions from different perspectives, examining how IHL can be translated into practical choices before, during and after new capabilities enter military use.
The Series
Against this backdrop, I am delighted to introduce a short series on AI and IHL. The series begins with this introductory post and continues with three contributions, each approaching the subject from a different angle: procurement and legal review; the practical teaching and application of IHL within armed forces; and the broader direction in which debates on technology and IHL may now be moving.
The series also looks back at the discussions held in late spring this year, with the contributions growing out of the panels, presentations and informal exchanges that took place at CyCon 2026 in Tallinn in May. This year, the Conference on Cyber Conflict celebrated its eighteenth anniversary—officially reaching adulthood—which offered a fitting opportunity to reflect on what the conference has become. CyCon is no longer simply a sequence of expert panels on technical or legal questions. Over time, it has developed into a close-knit community that brings together military practitioners, government officials, academics, industry representatives, and technologists where many participants return year after year, while new voices continue to join the conversation and reshape it.
That evolution matters because cyber conflict can no longer be discussed in isolation. Although CyCon remains, as its name suggests, a conference on cyber conflict, the boundaries of that field have become increasingly fluid and permeable. Cyber capabilities are now embedded in wider military operations, intelligence processes, communications systems and decision-making structures, as is increasingly the case for AI. Developments happening in the private sector are being incorporated into military systems at considerable speed, from intelligence analysis, and target recognition to autonomous navigation and decision support. Much of the most advanced technical expertise remains outside government, which makes closer cooperation between the public and private sectors both unavoidable and desirable. Yet cooperation alone is not enough. States and companies must also develop a clearer shared understanding of legal responsibility, operational risk, and the conditions under which AI-enabled systems may lawfully be designed, acquired, and used.
Therefore, the first contribution, by Dr. Anke Allenhöfer, begins at precisely this point. She examines the procurement of military AI capabilities through both external and internal models of governance and considers how Article 36 of Additional Protocol I can inform defence acquisition. Her article develops the argument she advanced in her CyCon 2026 proceedings paper, “Procuring Tomorrow: IHL Compliance as a Strategic Factor in Military AI Procurement.” Procurement is a strategic point at which the State’s legal obligations meet private-sector technological development, allowing legal requirements to shape how a system is designed, acquired, and supported throughout its lifecycle. Contracts, testing requirements, audit mechanisms, and continuing access to information can translate IHL obligations into concrete technical standards. They can also ensure that compliance is revisited as systems are updated, retrained, or used in operational settings that differ from those originally anticipated. Article 36 review should therefore form part of a broader system of oversight that continues throughout the capability’s lifecycle.
The second contribution turns from procurement and review to the practical challenge of making IHL work within military organisations. At CyCon 2026, Colonel Inna Zavorotko spoke on the panel “Battle Without Borders: Cyber Warfare and the Law in Multi-Domain Operations,” which examined how international law operates across an increasingly interconnected battlespace. Drawing on Ukraine’s experience of Russia’s full-scale invasion, Colonel Zavorotko examines how international law operates across an increasingly interconnected battlespace, where cyber capabilities, algorithmic tools, and integrated sensor networks shape operations on land, at sea and in the air. Her contribution considers how IHL can be translated into operational practice when decisions are made under intense pressure and cyber activities form part of almost every military operation. It also explores the role of military legal advisers as interpreters between IHL and battlefield reality, and why effective implementation depends on more than legal advice at senior levels. Training, national legislation, and the integration of legal considerations throughout command structures are therefore all essential.
Building on these institutional dimensions, a final contribution by Professor Rain Liivoja brings the various strands of the discussion together and places them in a broader perspective. His post considers the wider IHL conversations that emerged during CyCon 2026 and what they may tell us about the direction of travel. One question is whether new technologies are placing the established rules of IHL under strain, or whether the greater challenge lies in translating those rules into system design, procurement, doctrine, training, and operational practice. Another concerns the growing overlap between physical and digital protection. Medical services, humanitarian organisations, and cultural property increasingly depend on data, networks and digital infrastructure, even though the legal status of data itself remains contested. The discussions on the digital emblem, which Professor Liivoja moderated, offer a particularly useful example. A digital marker may help armed forces identify protected infrastructure in cyberspace, but it cannot by itself create respect for the protection that IHL already provides.
Concluding Thoughts
Large-scale treaty reform remains difficult, while technology and military practice continue to develop. In that setting, legal change may emerge more gradually through weapons reviews, standards, military manuals, operational guidance, national legal positions, and the day-to-day work of legal advisers. The challenge is to ensure that IHL can govern AI and cyber operations in practice as decision-making accelerates, infrastructure becomes more interconnected, and responsibility is increasingly shared among States, armed forces, and industry. Taken together, the three contributions highlight where the most important work is now taking place: before systems are acquired; within the institutions that use them; and through the continuing interpretation of IHL as warfare evolves.
Many of these questions are likely to remain with us for some time as technology continues to develop and military practice evolves alongside it. Their persistence reflects the pace of change rather than any weakness in IHL. It has had to respond to new weapons and new methods of warfare before, and many of the issues raised by AI are, at their core, familiar ones, whether the information behind a decision is reliable, whether legal review is being carried out seriously rather than as a formality, and whether the people making operational decisions still have enough time, knowledge, and authority to exercise real judgment. The existing framework is capable of addressing these concerns, but only if its rules are translated into practice and treated as part of the way military systems are designed, acquired, and used.
There is also good reason to be optimistic, because the same technologies that create new risks may also help armed forces comply with the law more effectively. AI can support the identification of lawful targets, help decision-makers understand the likely consequences of an attack, and improve the protection of civilians, medical services and other protected persons and objects, provided that it informs human judgment rather than taking its place. Much of the work needed to make that possible is already under way, through procurement processes, weapons reviews, doctrine, training, and the daily work of those who advise commanders and help turn legal obligations into operational decisions. In addition, discussions taking place internationally reflect encouraging steps towards a shared approach to the responsible development and use of military AI systems.
The contributions that follow are written in that spirit. They approach the subject from different directions but they share the view that the law is capable of meeting this challenge and that responsible use of AI is achievable.
Finally, I would like to express my sincere gratitude to the Lieber Institute and the Articles of War team for hosting this series, and I hope the contributions that follow will encourage a practical discussion about how international law can guide the responsible use of AI in armed conflict.
***
Maria Tolppa is a researcher and analyst in the Law Branch of the NATO CCDCOE.
The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.
Photo credit: U.S. Army, Sgt. Marc Morgenstern
