When the Defender Is the Attacker and Does It Matter?
I was delighted to learn that Dr Jonathan Kwik has received funding for what promises to be a most important research project. Jonathan is fast developing a well-earned reputation as a thought-leader in complex areas associated with emerging technologies; for the purposes of this piece the focus is on artificial intelligence (AI). The research will examine the “measures taken to anticipate, counter, mitigate, or reduce the risks posed by enemy AI systems.” It will address how “the law-of-war, international human rights law, and ius ad bellum regulate defences against adversarial use of military AI.” Details of the Project are available here; clearly the Project is designed to delve more deeply into the issues identified in Dr Kwik’s article published in the International Review of the Red Cross (see here).
This is a major undertaking, and it will be interesting to see how the research Project evolves. The issue is of course highly topical. In the Russia v Ukraine War, for example, electronic warfare is being used to cause inbound missiles to miss their targets. So the topic has clear current operational relevance. In the following paragraphs, I offer a couple of thoughts, but these are very brief and distinctly preliminary musings.
Applicable International Law
Jus ad Bellum
Taking UN Charter law first, the notions of greatest relevance are the prohibition on the threat or use of force under Article 2(4) and the inherent right of forceful self-defence in response to an actual or imminent armed attack. A hypothetical scenario illustrates several useful points concerning the operation of the Charter. For example, if State A takes non-forceful action with no adverse consequences for third party States and with the purpose of restricting or preventing the ability of State B to use AI-enabled force against it, the taking of that action will not per se amount to a use of force by State A, neither would it amount to an armed attack. Of course, other action by State A might constitute a threat of force, but simply taking such defensive precautions to restrict or prevent the ability of State B to use force against it will not, of itself, constitute a threat to use force.
But does it make a difference if the defensive measures consist of deflecting missiles so they fall on neighbouring State C territory? If a missile that is deflected in this way were to cause death, injury or damage, would State A or State B or both have breached Article 2(4)? What are the factors to consider, and who decides the issue? Numerous sub-issues arise, including whether it makes a difference whether State A (and/or State B) knew in advance that the missile would be diverted to State C? The relevance or otherwise of intent, recklessness or negligence and numerous other pertinent issues are excellently addressed by Tsvetelina van Bentham and Michal Schmitt here, but further discussion of those matters lies outside the limited intended scope of the present piece.
Jus in Bello
Once an armed conflict is under way, the focus in international law terms shifts to the law of armed conflict, and in particular to the principle of distinction, the prohibition of indiscriminate attacks, notions of proportionality and to the requirement on all parties to an armed conflict to take precautions in attack and against the effects of attacks.
Interference with a weapon system that employs AI raises complex issues starting with the very notion of attack. The Additional Protocol I (AP I) Article 49(1) definition of attack refers to “acts of violence against the adversary.” Clearly the firing of a weapon such as a missile by State B against State A amounts to an attack. Imagine, however, that State A is able to take control of the weapon in mid-flight, or in some way to interfere with the AI control of the weapon, or perhaps merely to deflect the weapon from its planned target. Do any of these levels of interference have the effect of causing State A to become the attacker? If the interference by State A consists of taking complete control of the weapon, there is a strong argument for saying that State A has become the attacker if State A then uses the relevant weapon to cause death, injury, damage or destruction to State B.
Earlier reference was made to interference which merely causes an AI-enabled weapon system to be deflected from its intended target. If this is done without the deflected weapon being specifically directed against an alternative target, it may be difficult to characterise the act of deflection as an attack. In a sense, mere deflection would not be interpreted as a violent act and the act of violence and the violent actor would remain the State firing the weapon, State B. If those interpretations can be agreed, there are numerous circumstances in between where it is likely to prove difficult to distinguish between attacker and victim of attack. Dr Kwik’s Project will, it is hoped, introduce some clarity here.
Another of the many issues that arise concerns the precautions that are prescribed under Articles 57 and 58 of AP I. A key question will be whether the employment of AI, whether in connection with attacks or to enable interference with AI-controlled weapons, is consistent with the proper performance of these precautionary tasks. There is a rich debate as to the acceptability or otherwise of the employment of AI in targeting – see for example here, here, and here. There are thorny issues there to examine and, it is hoped, to solve.
International Criminal Law
The technologies to be discussed in this Project do, of course, have implications in other areas of law, not least international criminal law. Complex questions will arise as to the identity of the perpetrator, for instance was the perpetrator of the attack the individual who fired, or ordered the firing of, the weapon, or was it the person who interfered with the functioning of the weapon’s AI system? That may of course depend on the nature of the interference. Does it make a difference if the AI in State B’s weapon system identified and selected the target for attack and if it was an AI-controlled State A defensive system that interfered with the State B weapon’s AI, thereby causing it to attack civilians? Assuming the availability of relevant evidence, can international criminal law be sensibly applied in such a scenario?
Concluding Thoughts
There are many intricate legal issues to be addressed, and answers are now needed as the technology is rapidly moving from the science lab to the battlefield. I wish Dr Kwik every success with his Project!
***
Air Commodore William H. Boothby retired as Deputy Director of Royal Air Force Legal Services in July 2011. He is Honorary Professor at the Australian National University and also teaches at the University of Southern Denmark and at the Geneva Centre for Security Policy.
The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.
Photo credit: Paris Bilal via Unsplash
