Rethinking Proportionality in the Cloud Age: Reverberating Effects of Attacks on Data Centers

by | Sep 10, 2026

data centers

Few issues have attracted more attention in contemporary targeting law than reverberating effects from attacks. Much discussion has focused on attacks against traditional critical infrastructure—particularly on electrical power systems—where civilian harm may extend well beyond the immediate area of physical destruction. Kinetic attacks against commercial hyperscale data centers suggest that the next challenge for proportionality assessments lies in the digital infrastructure through which such effects may be transmitted. As military reliance on commercial cloud services grows, so too does civilian dependence on that infrastructure.

The prospect of such attacks became operational reality in March 2026, when Iranian drone strikes damaged Amazon Web Services (AWS) data centers in the United Arab Emirates and Bahrain. Although the physical damage was geographically limited, the incident demonstrated how a strike against a data center could interrupt cloud services supporting governments, businesses, and critical infrastructure. It also illustrated that significant civilian consequences may arise not only from destruction of a facility, but through disruption of cloud services extending beyond the point of physical impact.

Recent scholarship has appropriately focused on whether commercial cloud infrastructure may qualify as a military objective under the law of armed conflict (LOAC). As armed forces increasingly rely on commercial cloud providers for communications, intelligence processing, logistics, command and control, and artificial intelligence-enabled capabilities, some data centers may satisfy Article 52(2) of Additional Protocol I. That debate is necessary. Yet military objective status answers only one question in the targeting process. A further question is whether expected incidental civilian harm—including reasonably foreseeable reverberating effects—would be excessive in relation to the concrete and direct military advantage anticipated.

The applicable harm threshold must be clear. Under Article 51(5)(b), the proportionality rule concerns incidental loss of civilian life, injury to civilians, damage to civilian objects, or a combination thereof. Under the narrow view provided by AP I—consistent with prevailing targeting practice—the interruption or degradation of a cloud service does not, without more, constitute such harm. Temporary loss of access to data, computing capacity, or online services does not necessarily enter the proportionality calculation in its own right. Such disruption only becomes relevant where it is reasonably expected to result in one or more of the recognized forms of incidental civilian harm.

Broader views have been advanced as to whether loss of functionality may itself constitute damage, particularly in the cyber context. This post does not seek to resolve that broader debate. Instead, it asks how reverberating effects from attacks on data centers should be assessed within the more limited harm threshold described above. It argues that existing proportionality law encompasses those effects where cloud-service disruption is reasonably expected to result in civilian death, injury, or damage to civilian objects. The challenge is not to lower the existing threshold, but to determine when disruption may reasonably be expected to produce harm that already falls within it.

Military Objectives: Only the First Question

Whether a commercial data center qualifies as a military objective depends not on civilian ownership or use alone, but on whether it makes an effective contribution to military action and whether its destruction, capture, or neutralization offers a definite military advantage in the circumstances ruling at the time. Given armed forces’ growing reliance on commercial cloud providers, some data centers may satisfy these criteria. Identifying a military objective, however, is only the beginning of the analysis.

Commanders and legal advisers must also assess whether expected incidental civilian harm would be excessive in relation to the concrete and direct military advantage anticipated and must take all feasible precautions in attack. For conventional targets, estimating that harm commonly involves blast effects, fragmentation, structural collapse, and risks to nearby civilians and civilian objects. Commercial cloud infrastructure, however, requires the assessment to extend beyond effects that are immediately visible at the target location.

Commercial hyperscale data centers present a distinctive operational reality. Their military value may derive from services provided to armed forces, while the same infrastructure supports hospitals, emergency responders, transportation systems, governments, businesses, and private users. Consequently, neither the target’s military significance nor its potential civilian consequences can be understood solely from its physical characteristics.

The relevant inquiry is not simply whether disruption will affect civilian users, but whether it is reasonably expected to cause legally recognized harm. Temporary unavailability of an online banking service, government website, or remotely stored data would not, without more, satisfy the threshold adopted here. By contrast, disruption of an identifiable cloud service may become relevant where it is reasonably expected to disable a hospital function and result in civilian death or injury, or to cause physical civilian infrastructure to malfunction and sustain damage. The difference lies not in the applicable law, but in the factual pathway connecting the attack to the ultimate harm.

Applying Existing Proportionality Principles

Electrical infrastructure provides a useful analogy. In assessing an attack on a power-generation or transmission facility, commanders do not necessarily count loss of electricity itself as injury to civilians or damage to civilian objects. Rather, they consider whether the interruption is reasonably expected to produce such consequences. Loss of power may disable life-support equipment or cause physical infrastructure to malfunction. Proportionality analyses may therefore extend beyond immediate physical effects while remaining anchored to the harm threshold in Article 51(5)(b).

Cloud infrastructure operates similarly. Rather than distributing electricity, data centers provide computing, communications, storage, and networking capabilities. A strike may cause limited destruction at the point of impact while interrupting services used by geographically distant civilian systems. The interruption nevertheless remains a causal pathway, rather than necessarily constituting the legally relevant harm in its own right. The harm entered into the proportionality assessment is the resulting civilian death, injury, or damage, not merely the preceding loss of service.

This distinction limits the scope of the argument. Economic loss, social inconvenience, diminished administrative capacity, and loss of access to digital services do not become incidental civilian harm merely because they are foreseeable. The inquiry remains whether a consequence falls within the recognized harm threshold and may reasonably be expected in the circumstances prevailing at the time.

For purposes of this post, a “sufficiently close” causal relationship provides an analytical means of distinguishing reasonably expected death, injury, or damage from consequences that are speculative, highly remote, or dependent upon an indeterminate sequence of intervening events. It is not proposed as an additional legal test and does not alter Article 51(5)(b). Its function is explanatory and limiting: it helps distinguish harm that may reasonably be expected to result from anticipated cloud-service disruption from harm that depends upon an uncertain chain of remote contingencies.

Identifying the harm relevant to proportionality therefore proceeds in two stages. First, the anticipated consequence must constitute loss of civilian life, injury to civilians, damage to civilian objects, or a combination thereof. Second, that harm must be reasonably expected on the basis of information reasonably available when the targeting decision is made. Once identified, the expected harm must be compared with the concrete and direct military advantage anticipated.

Applying Reasonable Foreseeability

Reasonable foreseeability describes the prospective character of the second stage. It neither expands the recognized categories of harm nor reduces the treaty formulation—harm that “may be expected”—to the mere possibility that harm could occur. The question is whether a reasonable assessment of the information available before the attack supports an expectation that legally recognized civilian harm will result.

This assessment is particularly difficult for commercial cloud infrastructure. Hyperscale data centers support constantly evolving military and civilian functions that may be neither physically visible nor readily identifiable from the target itself. A single facility may support both military operations and multiple civilian functions through shared infrastructure. Some dependencies and downstream consequences will therefore remain uncertain or unknowable before an attack. The law does not demand perfect prediction, but reasonably available information about those dependencies cannot be disregarded.

Accordingly, the assessment must extend beyond the target’s physical characteristics to identifiable functions supported by its cloud services. This does not require commanders to identify every customer or map every digital dependency. Nor does it require consideration of speculative or highly remote consequences. The question is whether, on the information reasonably available at the time, disruption of identifiable services is reasonably expected to result—not merely in service degradation—but in civilian death, injury, damage to civilian objects, or a combination thereof.

Relevant information may include: the nature of the affected services; the identity and functions of known civilian users; the degree of civilian dependence; the availability of redundancy, backup systems, or alternative providers; and the expected scope and duration of disruption. A brief interruption affecting a service with effective redundancy may present little reasonably expected risk of legally relevant harm. A prolonged disruption affecting an identifiable hospital function without an effective alternative may support a different assessment.

The analysis therefore separates three questions. Does the anticipated consequence satisfy the applicable harm threshold? May that harm reasonably be expected on the basis of information available before the attack? If so, would the expected harm be excessive in relation to the concrete and direct military advantage anticipated? Reasonable foreseeability identifies the harm entering the proportionality assessment; it does not determine the outcome of the proportionality comparison.

Conclusion

Addressing the challenges posed by commercial cloud infrastructure does not require redefining incidental civilian harm. Interruption of a cloud service does not, without more, constitute the form of incidental civilian harm examined in this post. It becomes relevant where it is reasonably expected to result in the loss of civilian life, injury to civilians, damage to civilian objects, or a combination thereof.

What has changed is the operational environment in which this rule must be applied. The military value of a data center and its potential civilian consequences may depend upon digital relationships that cannot be understood from the facility’s physical characteristics alone. Commanders and legal advisers may therefore need to examine the civilian functions supported by the targeted infrastructure, the consequences of their disruption, and the availability of effective alternatives.

This approach neither includes every downstream consequence nor excludes harm merely because it occurs indirectly. It distinguishes loss of service from resulting death, injury, or damage to civilian objects and excludes consequences that fall outside the harm threshold or are speculative or highly remote. Where legally recognized harm may reasonably be expected, it must be compared with the concrete and direct military advantage anticipated.

Attacks against commercial data centers therefore present a challenge of legal application rather than legal innovation. Meeting that challenge requires an informed assessment of whether disruption of cloud services may reasonably be expected to produce civilian harm that existing proportionality law already requires commanders to consider. As military and civilian reliance on commercial cloud infrastructure continues to grow, military legal advisers will play an increasingly important role in supporting such operational planning and targeting decisions.

***

Shundai Akiyama is a Major in the Japan Air Self-Defense Force.

The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.

Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.

 

 

 

 

 

 

 

 

Photo credit: Getty Images via Unsplash