Federated Front: AI-Assisted Targeting, the Rendulic Rule, and Multi-Domain Operations

by | Sep 11, 2026

Rendulic rule

Consider the following scenario in the not-so-distant future: the Suwałki Gap, Autumn, 203X. In a desperate test of the North Atlantic Treaty’s Article V, mechanized forces of the Russian 11th Army Corps guarded by pervasive electronic warfare (EW) measures probe the Suwałki Gap. This sixty-mile lifeline connecting Poland to Lithuania is the only overland route linking the Baltic States to the rest of NATO. A Multi-Domain Command (MDC) U.S. headquarters, fusing space-based sensors, tactical drones, cyber effects, and long-range fires, is responsible for specialized effects to deny and degrade the enemy. Communications are intermittent as pervasive EW degraded the satellite link that a prior generation of Pentagon planners took for granted.

To fight through this degraded environment, the MDC relies on a federated artificial intelligence (AI) system, a “Federated Front.” This system envisions forward computing nodes from low-earth orbit satellites to expendable drones collecting and processing information directly, minimizing the need to transmit raw data to distant hubs for analysis. Each node trains on local observations and shares model updates rather than underlying data. The result is a decentralized system that can continue improving even when individual links are disrupted.

The MDC’s AI targeting system flags a Russian mobile command-and-control (C2) node operating from a former industrial zone. The recommendation carries a high-confidence interval and an explainable rationale: a distinctive radio-frequency emission pattern; a thermal signature consistent with generator-powered command and control equipment; and the absence of any registered civilian or protected-emblem transponder. Due to downlink jamming, the most recent satellite intelligence available is two weeks old. Operating under the real threat of losing the Suwałki Gap corridor, the MDC commander authorizes a strike before the enemy C2 node can reach a hardened position.

Post-strike battle damage assessment reveals catastrophe. The adversary had purposefully distorted the sensor picture with algorithmic camouflage, masking a hospital’s protected signature and generating a synthetic emission profile inside it. Fifty civilians are dead.

Is the U.S. commander of the MDC criminally liable under the Uniform Code of Military Justice (UCMJ), and did the strike itself violate the law of armed conflict (LOAC)? Answering that question requires measuring the commander’s conduct against the law of war. While customary international law—such as the targeting provisions of Additional Protocol I recognized—and other treaties apply, the primary benchmark for this analysis remains the rules codified in the Hague Convention (IV) of 1907 which the Nuremberg tribunals applied. This post argues that a Federated Front architecture, disciplined through legal involvement, transforms a tragic outcome into a legally defensible one under the doctrine articulated in the post-Second World War Hostage case, known as the Rendulic Rule.

Architecture of LOAC Compliance

Any assessment of the strike begins with the core principles of the law of armed conflict.

Military necessity permits only that degree of force required to achieve a legitimate military purpose, in our case, the neutralization of an enemy C2 post. Nothing about the Federated Front’s recommendation exceeded that purpose; the category itself was lawful.

Distinction requires belligerents to direct attacks only at combatants and military objectives, not civilians. This is the principle placed under greatest strain by adversary countermeasures. The AI’s output was essentially a distinction judgment, an assessment that the object was military rather than civilian. The tragedy is that the judgment was corrupted by deception, not that the architecture failed to attempt distinction at all.

Proportionality prohibits attacks expected to cause incidental civilian harm excessive in relation to the anticipated concrete and direct military advantage gained. Before the spoofing was discovered, the anticipated collateral effect, based on available intelligence, was consistent with a legitimate strike on a C2 node.

Humanity forbids means and methods of warfare that cause unnecessary suffering or destruction to secure a military advantage. No such means or methods were employed.

Honor demands an adherence to ethical behavior in both offense and defense. As a foundational prerequisite for the law of war, it forbids conduct that constitutes a “breach of trust with the enemy.” No MDC conduct in this case suggests a breach of honor.

Taken together, these principles ask whether a strike, given what was knowable at the time, was reasonable. That framing is where the Rendulic Rule becomes relevant.

Rendulic Framework for Battlefield Judgments

In the Hostage case, a Nuremberg military tribunal considered a German commander’s scorched-earth withdrawal through Norway. General Rendulic, on the mistaken belief that Soviet forces were in closer pursuit than they were, ordered a destructive retrograde. The tribunal held that the commander’s action must be judged based on the situation as it appeared to him at the time, not based on after-acquired knowledge. General Rendulic’s mistaken assessment, the tribunal found, was one that a reasonably prudent commander could have made under the same circumstances. He was acquitted of the associated charge.

The Rendulic Rule has become a foundational feature of LOAC’s application to battlefield decision-making. It does not immunize recklessness, nor does it excuse a commander who ignores information or fails to make reasonable efforts at verification. It protects the commander whose reliance on the information reasonably available was itself objectively reasonable, even when that information later proves to be wrong.

The doctrine’s application to algorithmic warfare turns, as so much of the law does, entirely on the word, “reasonable.” A commander’s reliance on a “black box” AI system—where internal reasoning cannot be articulated—is difficult to characterize as reasonable in the way Rendulic requires. If a commander cannot explain, even in general terms, how a system produced a given output, the commander has failed to exercise any independent judgment. That is materially different from General Rendulic who could at least articulate the (mistaken) intelligence that drove his decision.

Opaque Models to Explainable Rationale

While a centralized model can be engineered into an explainable “Glass Box,” current versions remain opaque. Federated architectures, much like centralized models, are not inherently explainable; it is a deliberately engineered layer. In fact, the decentralized nature of the Federated Front requires greater transparency to oversee dispersed nodes. Yet the advantages of tactical edge computing outstrip the negatives. When properly designed and incorporating “Glass Box” interpretability, the Federated Front provides a transparent, human-readable ledger of factors underlying a recommendation. Rather than “target confirmed,” the system in the Suwałki scenario provided an explainable rationale, tying the recommendation to articulable sensor indicators.

That explainability is not a public-relations feature, but the predicate for Rendulic protection. A commander who can testify to legitimate reasons the system flagged the target—and shows those reasons were what a reasonably prudent officer would rely on—occupies the same legal position as General Rendulic. Here, a good-faith actor operated on the best information reasonably available, proven wrong by circumstances outside their control. Explainability transforms an unreviewable strike of faith into a reviewable act of judgment.

Federated architectures are also well suited to producing this kind of output because they push learning to the tactical edge without requiring every gradient update to pass through a single, unaccountable model. Techniques increasingly available for interpreting AI networks translate “neurons” into human-interpretable features, offering a path to genuine explainability. This aligns with existing frameworks. Department of Defense Directive 3000.09 (2023), paragraph 1.2(2)(c), requires autonomous and semi-autonomous weapons systems to be designed with “technologies and data sources that are transparent to, auditable by, and explainable by relevant personnel.” AI targeting capabilities must be held to this same standard.

Legal Certification Protecting Commanders

Explainability alone does not establish that a commander’s reliance was objectively reasonable; a rationale can be transparent and still be built on a poorly constructed or inadequately tested model. Reasonableness demands an institutional baseline against which decisions can be measured.

That baseline should come from a dynamic Judge Advocate General (JAG) review of the Federated Front’s operational parameters. A higher-echelon JAG, working with technical specialists, reviews the model’s training data, its known failure modes, its explainability outputs, and the laws under which it will operate. This JAG must work hand in hand with the AI Operations Engineers wherever they are located, even at the cost of trading the targeting cell for the corporate office. This then verifies that the architecture’s outputs are of a kind a reasonably prudent commander may rely upon while synthesizing the military, technical, and legal expertise needed to oversee the system.

Once certification exists, the tactical commander is not distracted by repeated judgment calls about the trustworthiness of an unvetted AI algorithm in the middle of a high intensity conflict. The commander should be able to trust the apparatus that has already satisfied LOAC’s precautions requirement. This division of institutional labor is precisely what makes the reliance reasonable: the commander’s judgment operates within boundaries the law has already sanctioned.

Because federated models continue to learn at the edge, this certification cannot be a one-time event. It must attach to the bounds of permissible learning rather than to a single, static weight configuration: an “Allow List” and “Block List” of features the model may or may not act upon, checked against every update. Periodic re-certification calibrated to the operational tempo ensures that the JAG Corps remains vigilant in protecting the warfighter from falling into the information warfare traps.

Assessing Criminality in AI-Assisted Strikes

Returning to the Suwałki Gap scenario, the commander faces potential exposure under Article 18(a) of the UCMJ which asserts, “ … [g]eneral courts-martial also have jurisdiction to try any person who by the law of war is subject to trial by a military tribunal and may adjudge any punishment permitted by the law of war.” While 18(a) is a jurisdictional rather than punitive article, an American military tribunal is clearly able to sit in judgment for violations of the law of war, be they American or otherwise.

The “law of war” that Article 18(a) incorporates by reference is not confined solely to modern LOAC. Article 18(a) reaches back to the foundational treaty law codified in the Hague Conventions, specifically, under (IV) Respecting the Laws and Customs of War on Land and its annexed Regulations of 1907. The Nuremberg tribunal applied the Hague Regulations in the Hostage case.

Pointedly, Article 27 obliges attacking forces to take “all necessary steps” to spare “hospitals, and places where the sick and wounded are collected,” provided they are not military in nature. This mandate is reinforced and expanded upon by Article 18 of the Geneva Convention Relative to the Protection of Civilian Persons in Time of War (GC IV), which generally shields civilian hospitals from attack. Article 27 also places a reciprocal duty on the defender to mark protected sites by “distinctive and visible signs.” The adversary’s distortion of a hospital’s protected signature by fabricating a C2 emission profile is a defender-side breach of Article 27’s marking-and-good-faith obligations designed to make distinction possible.

Read together, the integrated Hague and Geneva frameworks confirm that criminal culpability under Article 18(a) turns on whether the commander took the steps the law of war “necessarily” and “reasonably” demanded, not on whether a protected object was in fact struck. This is the same inquiry the Rendulic Rule embodies, and it is the standard against which the commander’s reliance on the AI architecture must be judged. The DoD Law of War Manual explicitly adopts this standard, instructing that a commander’s decisions must be evaluated based on the circumstances and information reasonably available at the time, rejecting the clarity of hindsight.

Where a commander’s decision rested on an unverified, unexplainable black box, negligence is easy to find. We cannot accept delegation of a life-or-death judgment to a process a commander cannot explain or interrogate. Where the decision instead rests on a transparent output operating within certified learning bounds, and articulating specific, legitimate targeting indicators, the commander’s conduct becomes materially different. Here, an objectively reasonable reliance on the best information available at the time, later defeated by adversary deception rather than by the commander’s own negligence.

The table below illustrates liability outcomes of two different types of AI architecture:

Topaloglu table

Strategic Recommendations

First, rigorous adherence to Directive 3000.09 and the Ethical Principles for AI, specifically the requirement that AI development remain “traceable,” the United States should formally adopt “Glass Box” explainability as a mandatory acquisition and fielding requirement. For any AI targeting system intended for combat operations, this means interpretability tooling must be delivered alongside, not after, the operational model.

Second, the JAG Corps should nurture specialists capable of effectively advising commanders on AI to enable these specialists to work seamlessly with the Machine Learning Engineers.

Third, the U.S. Army Office of the Judge Advocate General should define permissible bounds of continuous learning rather than treating certification as a one-time approval.

Fourth, military education should train commanders on feasible precautions and the legal limits of AI-assisted targeting.

Lethality, Legality, and the Federated Front

The dual tyrannies of distance and data will define war on NATO’s eastern flank. Centralized, opaque AI architectures cannot survive contact with a capable and adaptable foe. A Federated Front, disciplined by explainability and echeloned JAG review, offers the United States a path to legal lethality. A commander who relies on a certified Glass Box, operating within its certified bounds, stands in the same legal position as General Rendulic, being judged on the reasonableness of the decision when it was made, not on hindsight.

***

CPT Mitch Topaloglu is a Judge Advocate in the U.S. Army, currently serving as the Deputy Officer in Charge of the Hohenfels Law Center at the Joint Multinational Readiness Center.

The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.

Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.

 

 

 

 

 

 

 

Photo credit: U.S. Army, Army Sgt. 1st Class Ari Shuemake