CyCon 2026 Series – CyCon Comes of (AI) Age
Editors’ note: This post introduces a series derived from panels and discussions that took place in 2026 at the 18th annual International Conference on Cyber Conflict (CyCon) event hosted by the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia. This year’s theme was “Securing Tomorrow.”
CyCon 2026 marked the eighteenth iteration of the NATO Cooperative Cyber Defence Centre of Excellence’s (CCDCOE) annual conference on cyber conflict. While CyCon has had more seasons than CSI or ER, it shows no signs of running out of material. Quite the opposite. As the theme of this series of posts suggests, the use of artificial intelligence (AI) in armed conflict has become a major focal area for CyCon. That should not surprise anyone considering the rapid global diffusion of AI, including in the context of national defence. And things are only getting started. The U.S. government alone is looking to spend more than $50 billion on AI-enabled military capabilities in fiscal year 2027. Many other advanced armed forces are also making major investments in AI, although comparable headline figures are harder to pin down.
Maria Tolppa’s introduction to this series drew out some of the applications of AI in the military domain and some of the associated risks and challenges. But the significance of AI for cyber operations can hardly be overstated. For one, AI has already transformed cyber activities by making them faster and more autonomous. AI has also been predicted to make cyber operations even more damaging, more sophisticated, and more precise. Indeed, one may hypothesise that AI will have an outsized impact on cyber conflict. Cyber operations are intrinsically digital, which removes some of the hardware-driven complications, notably sensing and actuation, that arise when integrating AI into physical military systems.
Furthermore, AI will not only be an enabler for cyber operations. It will also be a significant target for such operations. AI-enabled military systems, including decision support systems as well as cyber-physical systems, such as sensors, platforms, weapons or infrastructure, have novel vulnerabilities. These can be exploited through anti-AI countermeasures, which may take the form of cyber operations, including AI-enabled cyber operations. This prospect makes, among other things, the need to ensure the cyber resilience of advanced military systems more critical but also more complex.
CyCon 2026 touched upon some of the key governance issues of AI in the military domain more broadly. At the centre of this discussion sits the question about the appropriate human element in AI-enabled operations and the limitations arising for human judgement given the speed and opacity that characterise AI-systems. Considering these challenges, and despite popular suggestions that AI will help “fight the fog of war,” the discussions in various ways acknowledged that AI may in fact create a fog of war of its own.
Another common thread relates to the need to take a lifecycle approach to military AI governance and, in doing so, articulate an appropriate role for industry. This would ensure that capabilities are designed in a way that enables and even facilitates legal compliance in use, and that testing and legal review processes remain fit for purpose. Additionally, the practical examples given across the discussions clearly indicated that Ukraine has, for better or for worse, become a testbed for the development and deployment of advanced military technology. Dr. Anke Allenhöfer’s and Col. Inna Zavorotko’s thoughtful posts have already pulled on some of these threads.
Of Attacks and Data
At the same time, several legal issues remain evergreen. No question about the application of international humanitarian law (IHL) to cyber operations has resisted definitive resolution as stubbornly as the question about the lower threshold of an attack. This issue divided the international groups of experts drafting the Tallinn Manuals. Subsequently, it has elicited diverging views from States and prompted a lively academic debate. Unsurprisingly, the question surfaced at CyCon 2026 on several occasions, both in the presentations and the discussions.
The existing law defines attacks as “acts of violence against the adversary, whether in offence or in defence.” Such attacks are subject to various core IHL requirements, notably the principle of distinction, the rule of proportionality, and the obligation to take certain precautionary measures. This raises a question as to the kinds of cyber operations that constitute attacks for the purposes of IHL. Possible answers, organised from the most conservative to the most liberal, constitute something of a spectrum:
(0) A cyber operation does not amount to an attack because it does not, in and of itself, involve violence directed against the adversary.
(1) A cyber operation qualifies as an attack when it is reasonably expected to cause injury or death to persons or damage or destruction to (physical) objects.
(2) A cyber operation qualifies as an attack when it causes a functionality loss serious enough to require the replacement of physical components.
(3) A cyber operation (also) qualifies as an attack if, even in the absence of physical damage, it disables the target system’s functionality.
(4) A cyber operation may (also) constitute an attack if, even in the absence of any loss of functionality to a system, it corrupts or destroys data.
Nobody seems to be publicly endorsing position (0). But it is not impossible, of course, that it has some (silent) supporters, for instance among the States that refuse to engage in discussions about the application of IHL to cyber operations.
Each of the subsequent positions (1)-(4), however, enjoys some degree of support among States and in the broader expert community. Tallinn Manual 2.0’s Rule 92 notably adopted position (1), as it was the view enjoying unanimous support among the group of experts. That said, the majority of the experts viewed the need to replace physical components as a form of damage to the system and thus treated position (2) as an implication of position (1). Position (3) encapsulates a minority position among Tallinn Manual 2.0’s group of experts, involving a broader notion of loss of function. Finally, position (4) is linked to the proposition that data, at least under some circumstances, can itself constitute an object; this view has been advanced for years in the literature but has only more recently been adopted by several States.
As Col. Zavorotko explains, Ukraine has recently endorsed a combination of positions (1) and (2). But, interestingly, the Ukrainian Green Paper appears to treat this as a “middle position” between the “majority view” of Tallinn Manual 2.0’s group of experts and a “broader reading.” This seems to at least acknowledge the validity of the thinking of the members of the Tallinn Manual 2.0’s group of experts who, while endorsing position (1), did not go along with the loss-of-function approach in any form.
On one level, all of this is essentially a doctrinal conundrum, specifically a problem of treaty interpretation. The disagreement is about the proper textual construction of the terms “attack,” “violence,” and “object” in their context and in the light of the object and purpose of Additional Protocol I.
On another level, the persistence of the debate and the range of positions speak to the broader relationship between technological and legal change. In terms of the various types of legal problems that frequently follow technological change, the disagreement over the threshold of an attack provides a textbook case of uncertainty: the absence of anything approximating a consensus as to the legal consequences of particular novel conduct.
This particular uncertainty has not arisen (as it often does) because of the inherent vagueness or contestability of the terms of the legal rules. In this case, the contestability of the terms “attack” and “object” has been the consequence of a fundamental technological change that has made something, in this case digital data, highly valuable. Such a qualitative change would have been difficult for the drafters of Additional Protocol I to predict. Thus, this discussion also demonstrates how the technology-indifferent nature of specific rules can prove to be an inadequate safeguard against uncertainty driven by technological change.
Here, progressive development of the law would be helpful in addressing the uncertainty. But, as was also acknowledged across multiple CyCon panels, broader treaty reform in IHL remains unrealistic for the time being. Thus, the law must evolve through operational guidance, national legislation and publicly expressed legal positions. The legal significance of the positions that States have expressed in this context remains unsettled but, at a minimum, they serve as supplementary means for interpreting the relevant treaty provisions and amount to opinio juris for the purposes of establishing the existence and content of parallel rules of customary international law.
Digitising the Emblem
One context where there may be more hope for some coordinated development of the law relates to the “digital emblem.” In a nutshell, this is an initiative led by the International Committee of the Red Cross (ICRC) to develop a means of marking digital assets, including digital infrastructure, belonging to medical units to indicate their protected status under IHL. A 2022 report set out the benefits, risks, and candidate technical solutions. Subsequent consultations with States and other stakeholders led the project team to concentrate on the Authentic Digital Emblem (ADEM) solution. This was tested during the 2025 Crossed Swords exercise, conducted by the CCDCOE.
This project provides a good example of an initiative where success depends on close collaboration between different experts, as was discussed in some detail during a dedicated CyCon plenary session. The solution must obviously be technologically implementable and reliable. But the solution must also make sense operationally. For example, the digital emblem must be capable of being queried without this being detected, and it must be capable of being switched off where it may in fact become a source of operational risk. Finally, the solution must align with the overall policy objective and the legal framework. The next phase of the project, which seeks to move from concept development to operationalisation (including real-world testing, adoption, and implementation) was launched just weeks after CyCon closed in July 2026.
Understandably, the focus of the work so far has been on technological and operational feasibility. The legal paths to the adoption of the digital emblem remain open. The options include the adoption of a new additional protocol to the Geneva Conventions and a revision of Annex I of Additional Protocol I, which deals with the use by medical services of “distinctive signals” and communications.
Achieving this has been described as a “fraught task.” But there may be a couple of reasons for being hopeful. For one, the legal change would essentially be a technical one, which would not fundamentally affect the scope of existing protections. Furthermore, the adoption of Additional Protocol III to the Geneva Conventions on an essentially similar issue, the identification of medical persons and units by means of a new emblem, the red crystal, proved possible despite the sensitive political context. An amendment to Annex I of Additional Protocol I would, moreover, benefit from the simplified process prescribed in Article 98 of the Protocol.
At the same time, it is also important that the technical discussion does not get too far ahead of the legal and policy conversation. In particular, the digital emblem appears as a solution to the broad problem of the vulnerability of medical data. But, importantly, the physical emblem, to which the digital emblem is connected in terms of both terminology and intellectual history, is subject to a rigorous legal regime under existing IHL. In particular, not every medical professional, not every medical facility, and certainly not every humanitarian organisation qualifies for the special protection of medical services under IHL. Yet only medical personnel and medical units recognised as such under IHL are authorised to display the emblem.
Considering that the digital emblem is not intended to create new legal protections but to rely on those that already exist under IHL, its use would be similarly restricted. Accordingly, the digital emblem would not provide comprehensive protection to all medical and health data or digital infrastructure. This creates a dilemma: being clear about the significant legal constraints on the eventual use of the digital emblem may prove to be counterproductive when rallying support for it, yet doing so would help avoid confusion and disappointment further down the track.
By Way of a Conclusion
The international community uses disparate fora for multilateral discussions about the governance of different technologies in the military domain, including information and communications technology, AI, autonomous weapon systems, and space technology. In some instances, the same technology may be addressed in multiple parallel processes at the same time.
As an interdisciplinary multi-stakeholder gathering, CyCon can play a role in facilitating discussions across various military technologies from a cyber perspective. As the complexity of the technology and the governance frameworks increases, such cross-pollination becomes ever-more valuable. From that perspective, this year’s conference provided, one hopes, a taste of things to come.
***
Rain Liivoja is a Professor of Law at the University of Queensland.
The views expressed are those of the authors, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.
Photo credit: U.S. Army, Sgt. Marc Morgenstern
RELATED POSTS
New Technologies, Armed Conflict, and International Humanitarian Law
by Maria Tolppa
September 1, 2026
–
Governing Responsible Military AI Through Defense Procurement
September 1, 2026
–
September 4, 2026
