Beyond Human-in-the-Loop: Battlefield Maps for Drone Autonomy
The requirement that a human approve every lethal engagement, known as human-in-the-loop (HITL), is effectively dead, a casualty of the war in Ukraine. The requirement that commanders bear responsibility for the operations under their command, however, survives. The tension between those two sentences is the accountability gap identified when targeting decisions migrate into the machine, existing frameworks struggle to attribute responsibility for what the machine does. This post proposes a framework to close that gap.
The human responsibility the law demands should relocate from individual targeting episodes to a combination of program selection and map designation. That is, commanders should bind levels of machine autonomy to certified system capabilities and to risk-classified, time-bounded areas of the battlespace.
Human-in-the-Loop on the Modern Battlefield
HITL control assumes three things: a communications link; time to decide; and an operator with attention to spare. The war in Ukraine has undermined all three assumptions.
Ukraine’s Unmanned Systems Forces commander describes a kill zone roughly 25 kilometers deep on each side of the line in which drone saturation makes movement close to suicidal. Other assessments put the belt at 15 to 20 kilometers and widening, with vehicle movement within it difficult to impossible. Inside that belt, jamming routinely severs the operator’s link, such that field drones’ automated terminal guidance—which completes the attack after contact—is lost. In such cases, the human contribution often ends at lock-on, hundreds of meters from impact. Where links survive, volume overwhelms attention. Operators report engagement tempos that exceed what they can meaningfully review. Ukraine’s stated trajectory features fewer operators, supervising more aircraft, and fully autonomous engagements.
The claim is not that HITL is never viable. Fiber-optic drones can provide an un-jammable link. And permissive environments still allow deliberate attack approval. Rather, the claim is that per-engagement human control cannot be the primary safeguard because the conditions it requires are precisely the conditions modern electronic warfare eliminates. A safeguard that survives only in ideal conditions is worse than none at all, because an operator approving machine-generated targets in seconds is not exercising judgment. It often amounts to laundering the machine’s judgment through a human signature. Insisting on HITL produces contradictions, as when the UK armed forces minister recently argued that there “must be a human in the loop” while also insisting it must be possible to “take the human out of the loop when required.”
Human Responsibility
Nothing can relieve commanders of responsibility for how a battle is conducted under their command. Regardless of how accurate targeting becomes, an AI system itself carries no ethical or legal burden. The law of armed conflict binds the humans who plan and direct operations, and a commander who employs an autonomous system is employing a weapon. The obligations of distinction, proportionality, and precaution remain the commander’s and the sponsoring State’s.
For this responsibility to be meaningful, it must attach to an act of judgment the commander actually performs. When the per-engagement decision disappears into the machine, an accountability gap emerges if the relevant decisions are not properly identified. Ethical and legal responsibility can only attach to human choices, so we must seek out and emphasize the choices that commanders can make at human speed with adequate information.
The question is not whether commanders remain responsible. They do. The question is which decisions we should attach ethical and legal significance to. Unfortunately, the answer is often lacking. For example, when NATO’s command-and-control community asks at what positions must the human remain responsible, they conclude only that the answer “depends on the impact of the decision at a given moment.” We need greater precision.
Program Selection
Part of the solution lies in selecting appropriate programs for the machines. A “program” here refers to everything a system is instructed to do before the trigger moment: the target classes it may engage; the engagement rules it applies; and the level of autonomy it exercises. Selecting the program is itself an act of human judgment. That decision is deliberate, recorded, and performed at human speed.
Program selection is already practiced at sea. Aboard Aegis warships, the commander does not approve every intercept. Rather, the commander selects among doctrines, mixing autonomy levels for different anticipated threats, and the system executes within the selected program. Former UK GCHQ director David Omand has proposed a general version: encode the law-of-war checklist as commander-assigned weights the machine optimizes across, logged and auditable, so that accountability follows “the commander who set the weights.” NATO air-power thinkers reach similar conclusions: the faster events run, the more the human moves from in-the-loop to on-the-loop, retaining a veto and reserving full autonomy for exceptional, pre-defined situations.
But the program cannot be the whole solution for several reasons. First, program selection may not be appropriate for all weapons systems. A warship is a slow-moving, largely defensive system with a high human-to-machine ratio, so waiting on a commander to choose the program is an option. For swarms of fast-moving offensive assets, the appropriate program can change block by block and hour by hour. Per-platform program changes quickly become impractical.
Second, the right program can change based on the environment. In a single sortie, an attack drone may cross an inhabited village, a friendly platoon’s position, and an empty stretch of enemy territory. One program may not be right for all three, and setting the program for the most conservative case surrenders most of the benefit that autonomy provides.
Third, changing a drone’s program mid-mission requires connectivity. As discussed earlier, the absence of reliable connectivity is one of the reasons we need autonomy in the first place. A program the commander cannot change when it matters is not sufficient.
Map Designation
A further part of the solution is based on another variable the commander controls: the battlespace. Autonomous systems should carry certified capability ratings reflecting the confidence we have in their ability to execute each program, and commanders should assign every portion of the operating area a risk classification with a matching autonomy ceiling, bounded in time.
In a cell classified as low-risk, i.e., containing no civilians and no friendly forces, a system rated for autonomous engagement of a defined target class may operate at full authority during a designated window. In a cell containing a hospital, the ceiling drops. Only higher-certified systems may make targeting decisions, autonomously if the machine and its operating mode carry a high enough rating, or under direct human control if they do not. A system traveling through these regions changes programs on its own, not because anyone sends it a message, but because it crosses a line on a map or a moment on a clock that was loaded before launch.
Position and time are workable control variables because enforcing them does not necessarily depend on a live link. A boundary loaded before launch travels with the aircraft, and systems such as inertial navigation and an onboard clock can continue functioning under jamming and GPS denial. Onboard navigation does drift when it is denied external references, but drift is a characterizable engineering quantity. It feeds the same certification logic: a system whose positional uncertainty exceeds a cell’s tolerance should not be certified to operate autonomously in that region. These systems can also be made fail-safe. When a window expires or a boundary is crossed, the system drops to its most restrictive mode until a fresh designation is loaded.
Militaries already govern lethality spatially and temporally. Kill boxes, activated and deactivated by time over grid-referenced cells, no-fire areas, restricted operations zones, and even declared minefields are all instruments by which a commander’s judgment about a place is made binding on weapons employment within it. Adding an autonomy dimension to fire support coordination measures extends a mature doctrinal grammar. This is also consistent with the law: distinction and proportionality are substantially judgments based on the environment. They depend on where civilians are, where the military advantage lies, and what a strike in this location risks. A spatio-temporal designation reflects that analysis.
Defense AI engineers already build architecture-enforced limits that hold “regardless of received instructions” for life-saving military drones. Applying them to weapon systems is consistent with existing practice. This answers the question of whether killer drones can “take morality onboard.” Ethical judgments can be encoded in the operating envelope.
Under a spatio-temporal designation regime, the commander performs a concrete, recorded act of judgment: classifying the cell; setting its autonomy ceiling against each system’s certified rating and operating mode; and activating it for a bounded window. Every boundary has an author, a rating, a timestamp, and an expiry. If an engagement inside an active cell goes wrong, an investigation asks answerable questions. Was the cell correctly classified when it was drawn? Was the certification honestly earned? Was the designation appropriate given operational needs? This helps close the accountability gap discussed above.
Objections and Limits
The hard ethical and legal problems do not disappear when we take program selection and map designation into account. Getting the designations right, and keeping them right as the battle moves, is the real work. There will always be a tradeoff between civilian risk and military effectiveness. Furthermore, certified ratings in themselves are no guarantee of safety. However, these are problems we are already familiar with. Staffs already produce and consume the intelligence that battlefield designations would require. Certification of autonomous systems will never be perfect, but it is a challenge we must face.
AI will also likely become better than humans at real-time cell classification. When this is the case, machine-drafted overlays should be welcomed. What must stay human are the decisions regarding programming and cell designation. Unlike per-engagement approval, these can be scaled to a granularity at which a human can deliberately review and decide.
Conclusion
Per-engagement human control is failing because it is proving untenable under extreme battlefield conditions. Pretending otherwise risks leading to a world where we launder machine judgment through human signatures when humans are not the true decision makers. We must focus our ethical and legal concerns on the decisions that battlefield commands will actually make.
Program selection, including setting weights, rules, or modes, is part of the solution. But alone it inherits the same fragile dependence on real-time human intervention. Pairing the program with the map, that is, binding autonomy levels to both certified ratings and risk-classified, time-bounded spatial designations, enables deliberate human judgment and traceable responsibility.
***
Michael Carey is the President of the American Society for AI (ASFAI), where he leads work on governance frameworks for artificial intelligence, including the AI Constitution project.
The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.
Photo credit: RBC-Ukraine
