Target Selection by Machines: The Duty to Verify and the GGE Rolling Text

by | Aug 25, 2026

Target

Editors’ note: This post is based on the author’s article “Target Selection by Autonomous Weapons Systems: What Does the Duty of Target Verification Require?,” published as an Exeter Centre for International Law Working Paper.

On August 31, the Group of Governmental Experts on lethal autonomous weapons systems (GGE) convenes in Geneva for its final session before it reports to the Seventh Review Conference of the Convention on Certain Conventional Weapons in November. On the table is the Chair’s June rolling text, which characterizes a lethal autonomous weapons system (AWS) as a combination of one or more weapons and “functionally integrated technological components that can identify, select, and engage a target” without intervention by a human operating the system.

The capacity to select a target without human intervention is the definitional core of an AWS. It separates such systems from decision-support tools, which inform human targeting decisions, and from weapons that merely deliver force against a target a human has chosen in advance. It is striking, then, how little attention the meaning of target selection has received. For two years, the Group has debated whether “identify” belongs in the characterization alongside “select” and “engage,” dropping the word in May 2025 and restoring it in December 2025. The Group has also debated whether the critical functions should be joined cumulatively or disjunctively. It has done so without settling what the underlying activity actually consists of.

The question matters beyond the definition of AWS. How target selection is understood determines when the precautionary duty of target verification must be discharged during the targeting cycle and by whom. Must the human operator verify? Or the system itself? This post pursues that question and draws out its consequences for the rolling text.

Target Selection is a Process, not a Single Decision

In ordinary usage, to select means to choose between alternatives. In military practice, that choice takes the form of a structured, multistage process. In NATO’s joint targeting cycle, political guidance defines which target sets may be considered at all. Target discovery locates and identifies entities of interest, target development assembles and characterizes them, quality control tests the supporting intelligence, and validation determines whether an entity is a lawful military objective. Validated targets are then nominated and prioritized, and immediately before engagement, tactical operators must acquire positive identification that the person or object about to be struck is in fact the validated target. Each stage filters the candidate pool. Dynamic targeting compresses the same criteria into the find, fix, track, target, engage, exploit, and assess sequence.

Target identification is equally distributed. The Chairperson’s 2025 background paper on the critical functions distinguishes identification performed before activation from identification performed after it, which ranges from finding new targets to matching a sensed entity against a preprogrammed profile and recognizing an intended target. Some identification tasks are by-definition performed by humans before launch, including choosing the criteria that define a category of targets, constructing the target profile the system will match against, and fixing the level of confidence a match must reach. Subparagraph 1A of the rolling text concedes as much when it provides that human determination of a set of potential targets or their characteristics does not exclude a system from the characterization.

It follows that neither identification nor selection is a fully automated function, even in a genuinely autonomous system. The productive question is therefore not which verbs to enumerate or how to join them, but rather which target selection tasks are performed by humans before activation, and which are delegated to the machine.

What the Duty of Target Verification Requires

Article 57(2)(a)(i) of Additional Protocol I requires those who plan or decide upon an attack to do everything feasible to verify that “the objectives to be attacked” are not civilians, civilian objects, or entities benefitting from special protection, but are instead military objectives liable to attack. The rule reads as if verification were a single undertaking. In reality, verification resolves into four constituent components: the attacker must gather information about the prospective target; assess the reliability of what has been gathered (the US Department of Defense (DoD) Law of War Manual lists reviewing the accuracy and reliability of the supporting information as the first of the feasible precautions); characterize the entity in law; and, finally, individuate the target by confirming that the entity so characterized is the entity against which force will be directed.

Individuation of the target is key. The duty of target verification attaches to the specific person or object to be attacked, not to a category in the abstract. Determining that mobile rocket launchers are military objectives by nature says nothing about whether the particular entity a sensor has detected is in fact a launcher, rather than an ice-cream van. The language of the rule points the same way, employing a transitive verb with a specific direct object. So does the drafting history: the International Committee of the Red Cross (ICRC)’s 1958 Draft Rules required both that objectives belong to a category of recognized military importance and that they be “duly identified.”

National practice confirms the reading. The Danish Military Manual extends verification to anything capable of shedding light on the specific nature of the individual or object concerned. The Norwegian Manual requires a planned attack to locate “the right person.” The DoD Manual demands confirmation that the object of attack is the intended target. The case law proceeds on the same footing. For example, the Appeals Chamber in Karadžić framed the test around what the attacker could reasonably have believed, on the information available, about the specific object attacked.

Where a human operator preselects the target, all four components of the duty can be completed before a weapon is deployed. By contrast, where target selection is delegated to an autonomous system, the four components of the duty cannot be completed at the point of system activation. The operator can carry out the legal characterization of the target category, build the profile, and set the confidence threshold. However, in any system that autonomously selects its own target, individuation must necessarily be performed by the system itself after it has been deployed. This means that the duty of target verification cannot be fully discharged by the operator at the time the system is activated.

Two fielded systems illustrate the resulting division of labour. IAI’s Harpy, an anti-radiation loitering munition, can be launched into a designated area without prior intelligence on any target’s location, where it orbits, searches for radar emissions, compares detected signatures against a stored library of hostile air-defence systems, and dives on a confirmed match, aborting if the radar stops emitting.

Human designers and operators have characterized active hostile radars as military objectives, assembled the signature library, and fixed the confidence a match requires. The weapon gathers the information, assesses the match, and individuates the emitter it attacks.

Rafael’s SPICE-250 goes further. Its automatic target recognition mode learns the characteristics of target types before a strike and matches what its electro-optical seeker sees against those learned representations, with the engagement of secondary targets left to user-defined policy. The division of labour is the same, but the machine’s share is larger, since classification proceeds by proxy features standing in for the legally relevant ones and the weapon’s tracking must bridge the interval between detection and strike. In both cases, humans complete the legal characterization in advance, while the system performs the information gathering, the reliability assessment, and the individuation.

Activation Is the Wrong Moment

The temporal structure of the duty of target verification has broader consequences. The proportionality rule prohibits attacks expected to cause incidental civilian harm excessive in relation to the concrete and direct military advantage anticipated. Neither limb can be assessed without knowing the nature, function, location, and surroundings of the actual target. The same holds for the duty to take all feasible precautions in the choice of means and methods and for the obligation under Article 57(3) to select the objective expected to cause the least danger to civilians.

Where selection has been delegated to an autonomous system, each of these obligations is only engaged, and can only be fully discharged, after, the system has been activated and has selected a specific target, not before.

The ICRC’s recent position paper on AWS takes the opposite view. Its starting point is that the rules on the conduct of hostilities presuppose context-specific human judgment, that it is humans who must determine the lawfulness of the attacks they plan, decide upon or execute and that these determinations “cannot be delegated to machine processes.” Because an AWS by definition selects and engages targets without human intervention after activation, the assessments reserved to humans can only be made before activation. The ICRC accordingly treats each instance in which a system selects and engages a person or object as an attack commencing at the moment of activation and requires users to satisfy themselves, at that moment, that every possible strike will be lawful, whoever or whatever triggers it, across the entire area and period of operation. The strict limits the ICRC proposes on target types, duration, geographical scope, and situations of use are the conditions under which such an assessment could realistically be made.

This approach runs into at least three difficulties. First, the position depends on separating technical tasks, which the ICRC accepts may be performed by machine, from the determination of lawfulness, which it reserves to humans. The duty of target verification does not divide neatly along those lines. A system that collects data through its sensors and matches it against a stored profile to a prescribed level of confidence is performing the information-gathering and reliability assessment that Article 57(2)(a)(i) demands. These components mix factual and legal determinations, and none is exclusively one or the other.

Second, the position overlooks the individuated character of the duty of target verification. Verification attaches to the specific entity against which force will be directed and is discharged in full only once that entity has been classified. At the point of activation, there is nothing yet to classify, so the duty cannot be completed then and remains engaged after the system is deployed.

Finally, the position sits uneasily with the ICRC’s own commitments. The paper endorses the proposition, drawn from the International Law Association’s study on the conduct of hostilities, that the anticipatory classification of objects as military objectives is impermissible because it “would negate the obligation to continually validate the nature of a proposed target.” It likewise insists that the information supporting precautionary decisions must be gathered and analysed up to the launch of an attack and, so far as feasible, while it is under way, and that instructions issued in advance do not by themselves amount to sufficient precautions.

If an attack by an autonomous system commences at activation, everything that follows takes place during its conduct. On the ICRC’s own account, then, something must be collecting and evaluating information after activation. In a system that selects its own targets, that something is the machine.

Taken to its logical conclusion, the categorical claim that legal determinations may never be delegated suggests that AWS are incompatible with the law. If every such determination must be made by a human before activation, and individuation can only occur after it, no AWS could ever be used in compliance with the law of armed conflict (LOAC). A few commentators accept that conclusion. The ICRC does not, since it recommends prohibiting only unpredictable and anti-personnel systems while restricting the rest. Nor do the States drafting the rolling text, whose two-tier architecture would be incoherent if every system within the characterization were unlawful by definition.

Designing for Compliance After Activation

If elements of the precautionary obligations can be discharged only after activation, those who plan or decide upon an attack have three options. First, the system could return control to a human operator to make the necessary legal assessments before engagement, together with the sensory information needed. However, reinserting a human at this point slows the targeting cycle and is operationally self-defeating.

Second, the tasks could be delegated to the system itself. However, this presupposes a level of technical sophistication that, in the case of proportionality’s contextual and value-laden judgments, is widely agreed to exceed what current systems can deliver.

Finally, the system could be programmed to disengage whenever a prospective engagement would implicate obligations beyond its compliance capabilities. This imposes the lightest technical demands, but comes at a real cost in operational utility, since the system would have to disengage not only where civilian persons are at risk, but also when civilian objects are expected to suffer incidental harm, since a proportionality assessment is required in either case.

Whichever route is taken, compliance is the product of a socio-technical whole comprising the system, its operator, and the decision-making process in which both are embedded. The rolling text captures this when it requires in paragraph 15C the critical functions of an AWS to be adequately predictable, reliable, traceable, and explainable. Those requirements set a threshold for delegation. A verification task may be assigned to a system only where the operator can anticipate in advance how the system will perform it and account afterwards for how it did.

Four Implications for the Rolling Text

Several consequences follow for the GGE discussions. First, the Group should drop the third verb in its characterization of AWS. The tripartite enumeration of identification, selection, and engagement assumes that these are self-contained functions, allocable wholesale to one side or the other of the human-machine divide. As the targeting process shows, neither identification nor selection is such a function. The disjunctive variants of the formula collapse for the same reason. A system that autonomously identifies and engages targets while humans make all the selection decisions is engaging preselected targets and is already excluded by subparagraph 1A, while a system that autonomously selects targets on the basis of wholly human-performed identification, including the positive identification of the specific entity, is for all practical purposes doing the same.

The Group should return to characterizing an AWS as a system that selects and engages targets, with selection understood inclusively to encompass identification, as the rolling text of May 2025 briefly did. An inclusive reading also answers the concern that a nominal human contribution to a single function could otherwise be used to defeat the characterization.

Second, the Group should retain subparagraph 1A. Its exclusions draw the boundary of the characterization at the determination of the specific target, which is exactly where the verification analysis places it. The duty requires the classification of the specific entity selected for attack. Human operators cannot perform that classification unless the target has been selected, and if they select it, the system is no longer selecting its target autonomously.

Third, the Group should make clear that paragraph 12A does not prevent legal determinations and assessments from being delegated to an autonomous system. The paragraph requires that such systems be operated under a responsible chain of command and control, “including ensuring assessment of legal obligations by a human.” Those words bear two readings. On the first, a human must be answerable for the assessment of the applicable legal obligations without necessarily performing every element of it. On the second, which reflects the ICRC’s approach, the assessment is reserved to human beings and may never be performed by a machine. Only the first reading is tenable. Nothing in Article 57(2)(a)(i) reserves the implementing activities to human beings. The second reading would defeat the instrument the Group is drafting. Since individuation cannot be performed before activation, a rule reserving every legal determination to human operators entails that no AWS can be used in accordance with the LOAC.

Finally, the multicomponent nature of the duty of target verification and the feasibility standard that governs it have implications for the notion of context-appropriate human involvement. Paragraph 12 requires human judgment and control at a level appropriate to the operational context and the characteristics of the system. Delegations have repeatedly objected that the concept is vague and understood differently across the room. In an ideal world, the Group would develop a consensus definition of the term and offer detailed guidance on how it is to be implemented. The likelier outcome is that the notion survives into the final report in its present form and that the work of specification passes to States. That would not be the worst outcome. A shallow, ill-considered definition would be worse than no definition at all, since it could skew subsequent specification by States in unhelpful ways. If the Group cannot agree on the detail, it should leave the concept open.

Conclusion

Much of the debate about military autonomy has been conducted through abstractions such as meaningful human control, which frame the problem, but say little about what compliance requires in concrete cases. Targeting practice points in a different direction. Target selection as a military enterprise and target verification as a legal obligation are both multistage processes whose components interlock across the human-machine divide and are co-produced. The line separating human from machine contributions is not fixed and tasks that remain with operators today may be delegated tomorrow. Regulatory formulas matched to today’s allocation will age quickly.

What does not change is that the LOAC imposes its obligations on human beings. The enduring question is whether a machine can perform a delegated task in a manner that satisfies the obligations of the persons deploying it. That requires embedding compliance into the design of these systems and translating the rolling text’s principles into concrete performance requirements. The Group’s task now is to produce a rolling text that serves as a solid basis for this work. This requires an accurate understanding of the process of target selection and the constituent elements of the duty of target verification.

***

Dr Aurel Sari is a Professor of Public International Law at the University of Exeter.

The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.

Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.

 

 

 

 

 

 

 

Photo credit: KGyST via Wikimedia Commons