VR Law — International Defence and Security Law — Vincent Roobaert

Who Signs Off?

Machine-speed targeting, procurement, and the Article 36 question

Vincent Roobaert ·

1. A faster decision loop and a legal review that needs to catch up

Recent advancements in military technologies highlight that the speed of decision is accelerating. The speed of decision has become a major selling point for defense companies. Anduril’s Lattice system, a software system allowing a human operator to supervise teams of robotic assets to perform complex missions, aims at «enabling warfighters to make better decisions, faster». Similarly, Palantir’s home page presents its Maven system as allowing «fast, agile decision-making» to «out-pace» the adversary. These systems are currently in operation and what they offer is a faster decision loop: a shorter interval between detection of the threat / target, its classification and the engagement.

This interval matters however, because it is where several core rules of international humanitarian law are actually applied. Distinction and proportionality, for example, are judgments that take time: time to assess what is being targeted, time to assess the risk of collateral damages and time to weigh anticipated military advantage against expected civilian harm. As that interval compresses, for valid operational reasons such as force protection and the need to keep pace with peer-competitor systems, the legal and institutional question becomes how a state satisfies itself, and demonstrates to others, that the judgment behind each engagement remains sound. This is a largely unresolved question of how existing IHL mechanisms apply to a new category of weapon systems.

This piece is about where that question currently sits and, since the author’s own background is on the procurement and legal review side, rather than the engineering side, what a state’s existing legal obligations already require it to do about it.

2. Investment and adoption are moving faster than the compliance question

The pace of change in the last couple of years has been extraordinary, driven by the war in Ukraine and in Iran. Defense-tech venture funding reached USD 14.6 billion in the first five months of 2026 alone, already ahead of the previous full-year record of USD 9.6 billion spent in 2025, with a handful of companies, such as Anduril and Palantir, attracting large shares of that capital. This reflects real demand: the military wants the capabilities these systems offer, and is procuring accordingly.

An interesting comparison data point from SIPRI’s Yearbook 2026 is worth underlining alongside that growth. When the United Nations Secretary-General solicited submissions for his report on AI in the military domain, he received input from 49 contributors, of which 31 came from states, down from 73 state submissions in a comparable 2024 exercise. Read together, these two data points suggest that the adoption and investment are moving fast while the multilateral policy conversation, at least measured by state participation, may be slowing down.

3. Legislators are trying to re-anchor human judgment in the loop

While AI military systems currently fall under an exemption in the EU AI Act, legislators in other countries are trying to address the matter. On 8 June 2026, US Senator Adam Schiff introduced the Human Authority in Lethal Operations Act («HALO Act»), which would require a designated human commander to hold ‘ultimate discretion’ over any use of force involving autonomous or semi-autonomous weapon systems, establish a formal review structure before such systems are developed and fielded (an obligation that already exists under Article 36 of Additional Protocol I to the Geneva Conventions), and require an updated review whenever a system’s core AI capabilities are materially modified.

Looking at this initiative, it is useful to distinguish between autonomous systems and AI-enabled decision-support systems, a distinction that is relevant because the two categories raise different legal questions and are not always governed by the same regulatory framework. Systems like Lattice or Maven are generally marketed as decision-support tools, rather than autonomous weapons in the strict sense. The practical question the HALO Act does not fully resolve is what ‘ultimate discretion’ means when the system available to the commander has already narrowed, ranked, and pre-filtered the available options at a tempo the commander did not (or cannot) set. The difficulty becomes even more acute when these systems fuse data from various platforms and sensors captured at different time-intervals, which questions the continued reliability of the data. The system will then document that the commander has signed off. However, it is a separate question whether the human was positioned to exercise the kind of informed judgment international humanitarian law contemplates.

4. What International Humanitarian Law asks of human judgment

The International Committee of the Red Cross position paper on autonomous weapon systems notes that the loosening of constraints on where and against what such systems may be used, together with swarm technologies and deeper AI integration into targeting, raises real questions about whether meaningful human control over the use of force can be maintained as currently practiced. In an earlier study, the ICRC explored what "control" should mean: a substantive, informed exercise of judgment, not simply a procedural sign-off appended to a machine-generated recommendation. Psychology will also play a role here, as commanders trust the system more and more and risk acting under confirmation bias.

As the initiative and leadership for developing such systems move from nations to private corporations, one has to wonder which rules apply to such development. The Montreux Document and the ICRC’s guidance for corporate compliance officers were developed with private security companies in mind, and contractors operating in or near conflict zones. They do not cover the development by private companies of system architectures through which a targeting decision is made. International Humanitarian Law was not built to address this point. Filling that gap should involve industry with a view of shaping what responsible design reasonably looks like.

5. Article 36 of Additional Protocol I and the practical challenge of reviewing a black box

International law already has an instrument aimed at assessing the legality of weapon systems. Article 36 of Additional Protocol I requires every High Contracting Party, in the study, development, acquisition, or adoption of a new weapon, means, or method of warfare, to determine whether its use would, in some or all circumstances, be prohibited by the Protocol or by any other applicable rule of international law. This is treaty text from 1977, and it applies without difficulty to the systems under discussion. The legal review anticipated by the HALO Act is fully in line with this legal requirement.

While the obligation exists, its implementation is uneven. Only a few states are known to maintain a formal Article 36 review mechanism. Article 36 also carries no transparency requirement of its own: a state’s review, if and where one takes place, is an internal process with no obligation to publish methodology or findings. Moreover, the review mechanisms were generally built for munitions and delivery systems governed by the laws of physics and whose effects could be assessed easily for distinction, accuracy and blast radius. They may be harder to apply to AI systems, which can be procured as ‘black boxes’ and/or whose outputs can be difficult to fully predict in a testing environment or highly dependent on the accuracy and quality of data fed to the systems.

The practical question for anyone advising on defense procurement, whether representing the state or the vendor, is therefore how a meaningful Article 36 review is actually conducted over a system built by a third party, where training data, model architecture, algorithms, and failure modes are commercially sensitive.

An equivalent review of an AI tool requires a different methodology altogether: one that depends on negotiated audit rights, appropriate security-cleared access for reviewers, and disclosure arrangements that protect the vendor’s legitimate proprietary interest while still giving the state enough visibility to discharge its own legal obligation. Moreover, as it is likely that the companies selling these systems will contractually impose waivers or limitations of liability on their purchaser, the latter must be confident that the system will operate within adequate legal constraints.

Getting the balance right between the private and public interests is a shared technical and contractual problem, not a one-sided one, and companies that can offer credible audit and security by design may find that it becomes a genuine commercial advantage if it can reassure the client that the system operates in line with international humanitarian law.

Sources

  1. https://www.anduril.com/news/anduril-unveils-lattice-for-mission-autonomy
  2. https://www.palantir.com/offerings/defense/army/
  3. https://www.linkedin.com/pulse/146-billion-5-months-defense-tech-vc-just-broke-every-hakan-kurt-l8btf/
  4. L. Bruun, J. Palayer and V. Boulanin, « Artificial Intelligence and international peace and security», SIPRI Yearbook 2026, at 445.
  5. https://www.schiff.senate.gov/news/press-releases/news-schiff-introduces-comprehensive-legislation-to-enact-commonsense-guardrails-for-defense-departments-use-of-ai/
  6. ICRC, Autonomous Weapon Systems and International Humanitarian Law, position paper (March 2026).
  7. ICRC, Decisions, Decisions, Decisions: Computation and Artificial Intelligence in Military Decision-Making, 2024.

First published on LinkedIn.