Operation Epic Fury, Regime Change, and the Collapse of Legal Constraint 

On February 28, 2026, the United States and Israel launched joint military strikes against Iran in what the Pentagon designated Operation Epic Fury. The operation came two days after the most substantive round of U.S.-Iran nuclear negotiations in years had concluded in Geneva, with both parties agreeing to continue talks. Within hours of those assurances, the bombs fell. Iran’s Supreme Leader Ayatollah Ali Khamenei was killed. Strikes targeted the Iranian president, military chief of staff, and extensive military infrastructure. A strike on a girls’ primary school in Minab reportedly killed nearly one hundred children between the ages of seven and twelve.

This article is not primarily about those facts, though they deserve full moral weight. It is about what those facts represent in the architecture of international law: not an aberration, but the latest and most severe instance in a deliberate, escalating pattern of U.S. policy that treats the prohibition on the use of force as optional, the Security Council as a procedural nuisance, and unilateralism as astrategic doctrine. From Venezuela to Iran, from Operation Midnight Hammer in June 2025 to the military raid on Caracas on January 3, 2026, to Operation Epic Fury in February 2026. The question for the international community is whether it will respond with proportionate seriousness or retreat, once again, into diplomatic ambiguity.

This article draws on the author’s prior analysis, examining U.S. strikes in Venezuela and the legal framework governing the use of force, as well as a companion analysis on civilian protection and the prohibition on the use of force in the Iranian context. It argues that the time for legal cataloguing alone has passed. What is needed now is a dual-track approach: constraint from within the United States, and constraint from without.

The Illegality is Not in Dispute

The legal analysis of Operation Epic Fury is straightforward. Article 2(4) of the United Nations Charter prohibits the threat or use of force against the territorial integrity or political independence of any state. Two exceptions exist: Security Council authorization under Chapter VII, and individual or collective self-defense in response to an armed attack under Article 51. Neither applies here.

The Security Council did not authorize the use of force against Iran. The United States did not request such authorization. Iran was not attacking the United States or Israel at the time of the strikes. Whatever residual concern might be derived from earlier Iranian actions had long ceased to generate an ongoing armed attack capable of activating the self-defense exception. Iran was, by all accounts, engaged in active negotiations. The U.S. Director of National Intelligence had testified as recently as March 2025 that Iran was not building a nuclear weapon and its supreme leader had not reauthorized the program suspended in 2003. The IAEA affirmed it had found no proof of a systematic weapons effort.

The strikes were also launched in violation of Article 2(2) of the Charter, which requires good faith in the fulfillment of Charter obligations. Launching military operations during active diplomatic negotiations, operations that the U.S. president had, days earlier, indicated would wait, is a breach of the most elemental duty of good faith that the Charter’s architecture depends upon. Iran’s Foreign Ministry characterized this correctly.

Separately, the stated U.S. objective of regime change, explicitly framed by President Trump as a goal of the operation, and echoed by Israeli Prime Minister Netanyahu, who declared the aim was to “remove the existential threat posed by the terrorist regime in Iran,” constitutes an independent violation of international law. The prohibition on forcible regime change is not a contested doctrine. It flows directly from Article 2(4)’s protection of “political independence” and from the customary norm of non-intervention. It is, in the language of the International Law Commission, a peremptory norm from which no derogation is permitted. 

A Pattern, Not an Episode

What distinguishes the current crisis from earlier controversies is not merely its scale. It is the administration’s explicit abandonment of any pretense of legal compliance. In the living memory of every diplomat, lawyer, and policymaker currently active in international institutions, the United States has consistently sought to present its uses of force as legally defensible, however strained those defenses sometimes appeared. The post-September 11 doctrines of preventive self-defense and the “unwilling or unable” standard were legally contested, but they were doctrines, attempts to operate within an interpretive framework rather than to discard it entirely.

In Venezuela, beginning in September 2025, the United States conducted lethal strikes against boats in the Caribbean, framing them as law enforcement operations to avoid triggering the War Powers Resolution. In January 2026, U.S. forces conducted a military raid into Caracas, killing dozens, capturing President Maduro, and announcing that the United States would “run” Venezuela until a new government was installed. The attempt to reframe a manifest use of armed force as a domestic law enforcement action is not merely legally incorrect; it is a deliberate attack on the conceptual architecture that makes international law legible.

The cumulative effect is the construction of a new operational norm, one in which the most militarily powerful state on earth reserves to itself the right to use lethal force anywhere, against anyone, for purposes it defines unilaterally, accountable to no external legal authority. This emerging pattern of blatant disregard of international law, if allowed to consolidate, will not remain the exclusive property of the United States. China, Russia, India, and regional powers are watching. Every precedent accepted becomes a precedent available. The erosion of the jus ad bellum (use of force) framework is a problem for every state that has historically relied on that framework for its own security.

The Regime Change Trap

Beyond the immediate illegality of the strikes, Operation Epic Fury has another grave problem: it has no plausible endpoint. With Khamenei dead and the Iranian command structure targeted, the power vacuum is not a side effect; it is the current situation. History provides no encouraging precedent.

The 2003 invasion of Iraq, similarly framed as targeting a dangerous regime with weapons of mass destruction, produced a multi-decade military presence, hundreds of thousands of civilian casualties, a regional security vacuum exploited by non-state actors, and a country that has never returned to the stability that even its imperfect prior condition represented. Libya in 2011 demonstrated that air operations designed to facilitate regime change produce state collapse, not democratic transition. These are empirically established outcomes.

Shajareh Tayyebeh school in Minab photos from Mehr (Abbas Zakeri, (CC BY 4.0))
Shajareh Tayyebeh school in Minab photos from Mehr (Abbas Zakeri, (CC BY 4.0))

Iran is a country of almost 90 million people, with a sophisticated military establishment, an extensive regional network of proxy forces, missile capabilities capable of striking U.S. bases throughout the Middle East, and a political culture that has historically rallied around national sovereignty under foreign pressure. The killing of Khamenei does not eliminate the Islamic Revolutionary Guard Corps. It does not dissolve the Quds Force. It does not prevent successor leadership from emerging. It may, as multiple analysts have noted, accelerate Iran’s determination to acquire a nuclear deterrent, the very outcome the operation was ostensibly designed to prevent.

President Trump has urged Iranians to “take over your government,” a statement that confuses aspirational rhetoric with operational planning. There are no credible exile groups capable of assuming state functions in Iran. There is no post-conflict stabilization plan of record. Instead, there are many indicators of a prolonged military engagement, regional escalation, and the kind of unsustainable occupation that has defined the two-decade aftermath of every comparable U.S.-led regime-change operation. 

A protracted military presence in Iran, even through proxy arrangements, would constitute one of the largest strategic and humanitarian failures in the history of modern warfare, in a country whose geography, population, and political culture make external occupation far more complex than any preceding U.S. intervention. International law prohibits this operation not because lawyers are squeamish, but because the legal prohibition reflects hard-earned collective wisdom about what such operations produce.

International Law Ignorance as Policy

It would be a mistake to treat the current administration’s approach to international law as simply incompetent or uninformed. The pattern suggests something more deliberate: a calculated decision that the costs of legal compliance exceed its benefits, and that U.S. structural advantages, Security Council veto, dollar-denominated global finance, and unmatched military projection capacity all insulate Washington from meaningful accountability. This calculation may not be wrong in the short term. What it ignores is the systemic consequence.

There is a further assumption embedded in this posture that deserves direct challenge: that the chaos generated by unilateral force can be managed, contained, and ultimately directed toward preferred outcomes. This has not proved true. The history of U.S. military interventions is a history of second and third-order effects that escaped prediction, planning, and control; sectarian fragmentation in Iraq that persists two decades on, state collapse in Libya that turned the country into a transit hub for migration and arms across the Sahel, and a counter-terrorism campaign in Somalia now in its third decade with no measurable endpoint.

Arleigh Burke-class guided-missile destroyer USS Delbert D. Black (DDG 119) fires a Tomahawk Land Attack Missile (TLAM) during operations in the U.S. Central Command area of responsibility, Mar. 2, 2026. Delbert D.
The USS Delbert D. Black destroyer fires a Tomahawk missile. (U.S. Navy Photo)

The assumption of controllability flatters the intervening power. It imagines that military and economic superiority translates into the capacity to shape political outcomes in deeply complex societies. It does not. Even the United States, with its unmatched alliance networks, its forward-deployed forces, its intelligence apparatus, and financial leverage, has repeatedly discovered that it can destroy a government far more efficiently than it can build a successor one. The chaos that follows the removal of even a repressive order does not wait for instructions. It does not respect the preferences of the power that unleashed it. And it does not remain contained within the borders of the state where it begins.

The international legal order, imperfect and unevenly enforced as it has always been, functions not because powerful states are compelled to obey it but because most states most of the time conclude that compliance serves their interests better than defection. The Charter system’s prohibition on the use of force exists because states recognized, after two world wars, that a world of unilateral military discretion produces catastrophic outcomes even for the powerful, and it persists because most states still recognize this truth. When the most powerful state in the system openly repudiates that framework, the signaling effect is global and immediate.

We are already observing the downstream consequences. Western partners have responded to Operation Epic Fury with studied ambiguity rather than unambiguous condemnation. France, Germany, and the United Kingdom issued a joint statement calling on Iran to negotiate, as if Iran were the aggressor, while carefully avoiding any characterization of U.S. and Israeli strikes as unlawful. Australia’s prime minister expressed support for the strikes as “acting to prevent Iran from obtaining a nuclear weapon.” These responses legitimate the legal theory underlying the strikes: that anticipated capability development, assessed by the striking state alone, constitutes sufficient grounds for military action against a country engaged in active negotiations. The logic, once accepted, has no limiting principle. It applies to any state that any powerful neighbor believes might at some future point develop threatening capabilities. Its adoption by Western governments is not a minor diplomatic concession. 

Inside the United States

The question that follows from legal analysis is not merely descriptive. It is operational: what can be done? The answer requires distinguishing between actions available within the United States and those available in the international system. Both tracks matter.

Within the United States, the War Powers Resolution of 1973 requires that presidentially initiated hostilities be reported to Congress within 48 hours and terminated within 60 days, absent explicit Congressional authorization. Operation Epic Fury has not been authorized by Congress. The administration’s prior pattern, invoking Article II Commander-in-Chief authority, is constitutionally contested and legally fragile. 

Congressional oversight mechanisms also provide near-term leverage. Appropriations authority gives Congress the power to prohibit the use of funds for specific military operations or for operations directed at the stated objective of regime change. The annual National Defense Authorization Act process, combined with supplemental appropriations, provides multiple leverage points. The New York City Bar Association has called explicitly on Congress to halt the administration’s violations of U.S. and international law in Venezuela; the same call applies with greater force to Iran.

Outside the United States

Following the Caracas raid of January 3, the Security Council convened in emergency session but produced nothing; no resolution was even tabled, because the structural reality of the U.S. veto foreclosed any attempt. This paralysis is itself the clearest evidence that the Security Council cannot currently function as a constraint on the United States.

The United Nations General Assembly retains authority under the Uniting for Peace procedure, established in 1950 for precisely the contingency in which Security Council paralysis prevents collective response to a threat to international peace and security, to convene emergency special sessions, pass resolutions characterizing the use of force, and authorize collective action short of binding enforcement. A General Assembly resolution characterizing the U.S.-Israeli strikes as a violation of Article 2(4) would carry significant normative weight, particularly if adopted by a large majority. 

States with sufficient institutional capacity should also consider referrals to the International Court of Justice (ICJ). While the Court cannot compel the United States to pay damages or halt operations; Nicaragua v. United States demonstrated in 1986 that a favorable ICJ judgment is unenforceable when the respondent holds a Security Council veto, an ICJ finding of illegality produces legal record of the highest authority, shapes subsequent customary law development, and imposes reputational costs that affect U.S. alliance relationships and diplomatic leverage across multiple issue areas.

The Responsibility to Respond Lawfully

This article has argued throughout for the legal constraint of U.S. military power. It is important to be precise about what that argument does not mean. It does not mean indifference to Iran’s internal repression. The Iranian government’s violent response to protests, its systemic violence against dissidents, and its documented human rights violations are real and serious. They generate legitimate humanitarian concern and justify a robust multilateral response.

What they do not generate is a unilateral legal entitlement for military intervention, including the intervention that has now occurred. Responsibility to Protect (R2P) was constructed within the institutional architecture of the Charter. It recognizes that sovereignty entails obligations, not only rights. But it equally and deliberately rejects the theory that individual states may determine unilaterally when intervention is justified. The moment humanitarian concern becomes accepted as a self-licensing basis for military action, it ceases to be a protection mechanism and becomes a standing authorization for the most powerful states to intervene wherever they characterize conditions as sufficiently dire.

International observers, United Nations mechanisms, and human rights organizations have documented patterns of lethal repression, arbitrary detention, and systemic violence against protestors and dissidents. Yet the existence of atrocity risk, however grave, does not create a unilateral legal entitlement for external military intervention.

The System Holds Only If States Make It Hold

Operation Epic Fury is not the end of international law. Breaches of law do not invalidate the law; if they did, no legal system could function. In 1986, the ICJ found the United States in violation of international law for its operations in Nicaragua. The United States vetoed Security Council enforcement. The law remained. What changed was the willingness of the international community to hold the line.

The current moment requires a similar choice. States that have spent decades insisting on their commitment to a rules-based international order must now decide whether that commitment is conditional on the identity of the violator. The ambiguous responses from London, Paris, Berlin, and Canberra suggest, so far, that it is. That decision, too, has consequences, not only for Iran, but for the precedents that will govern the next use of force, and the one after that.

Hossein Zohrevand for Tasnim News Agency
Damage on Tehran’s Ghandi Hospital after attack by the U.S. and Israel (Hossein Zohrevand for Tasnim News Agency)

The United States built much of the legal architecture now being dismantled. American lawyers, diplomats, and policymakers shaped the UN Charter, the Geneva Conventions, the Rome Statute, and the norms of customary international law that govern the use of force. The prohibition on the use of force was built on the ruins of the last catastrophe. The task now is to ensure it does not have to be rebuilt on the ruins of the next one.

Finally, there is a deeper conceptual error embedded in any sustained posture that disregards international order. National interest, properly understood, is not a free-standing concept that exists before and independent of international order. It acquires meaning and practical traction only within a system in which the interests of states are mutually recognized and can be pursued through stable frameworks of interaction. A state can have a foreign policy objective; it can identify resources it wishes to secure, alliances it wishes to maintain, and threats it wishes to neutralize. But the pursuit of those objectives, their translation into durable outcomes rather than momentary impositions, depends on a surrounding order that holds. When that order is replaced by an ad hoc revolving door of unilateral force and managed instability, national interest dissolves. The powerful state finds itself not in a world it controls but in a world it has made ungovernable, one in which its own preferences can no longer be reliably projected, its own commitments no longer credibly made, and its own security no longer structurally guaranteed.

Davit Khachatryan is an international lawyer and lecturer focusing on the intersection of armed conflict, emerging technologies, and international law.


Illegality without Consequences? Venezuela, Force, and the Erosion of Legal Constraint

The new year opened to the sound of airstrikes. On January 3rd, the world woke to reports that United States forces had launched a large-scale military operation against Venezuelan territory, an act that instantly sparked public debate, diplomatic channels, and professional legal discourse. The military operation, together with the broader policy choices of the United States, carries consequences extending far beyond Caracas, with profound implications for the future of force, legality, and authority in the international order.

United States forces targeted sites identified by Washington as integral to “state-backed transnational criminal and narcotics networks,” allegedly operating under the protection of the Maduro government. Operation Absolute Resolve was presented by U.S. officials as limited in scope and effect, and described as a lawful exercise of national security powers consistent with international law. The Trump administration relied on a highly controversial 1989 Office of Legal Counsel memorandum asserting that the President is not constitutionally required to comply with the United Nations Charter as a matter of domestic law, a position long regarded as incompatible with the United States’ international obligations.

The strikes, reportedly, achieved their immediate operational objectives and concluded without further escalation. Venezuela denounced the operation as a grave violation of its sovereignty and of the prohibition on the use of force under the United Nations Charter, rejecting the characterization of the strikes as law enforcement and calling for international scrutiny. These sharply opposed official positions crystallized the legal stakes from the outset. Absolute Resolve followed years of sanctions, indictments, and public accusations that steadily reframed force as an available policy instrument, setting the stage for a confrontation in which legality was asserted rather than debated, and consequences were left conspicuously undefined (DOJ; OFAC).

Draw the line, publicly and precisely. Key allies (UK, France, Germany, Australia, Japan, EU) should state clearly whether Absolute Resolve violated Article 2(4) and why, instead of generic “we support international law” language.
Refuse legitimacy through force. Maintain strict non-recognition discipline: do not treat leadership change, “transition authorities,” or “running the country” claims as legally effective if achieved through unlawful force.
Condition cooperation, don’t grandstand. Shift from denunciation to calibrated leverage: narrow intelligence sharing, operational coordination, basing arrangements, joint tasking, or capacity support where it is connected to unlawful uses of force.
Lock in the record at the UN. Push for Security Council debate, General Assembly action if the Council stalls, and formal letters and explanations of vote to prevent normalization through silence.
Reprice risk in trade and investment. Embed legality language in trade and regulatory engagement: heightened due diligence, compliance triggers, and contractual clauses reflecting instability created by unlawful force and occupation-type administration.

Everything turns on a basic rule that the system cannot afford to lose: no State, however powerful, may act as nemo iudex in causa sua; “no one is judge in his own case”. As long as the international rules-based order continues to breathe, however laboured that breath may now be, the legality of State conduct cannot be determined unilaterally by the acting State itself. International law rests on the fundamental premise that legal assessment is external, contestable, and grounded in shared normative frameworks rather than sovereign assertion. It is objective legal analysis, not official narration, that determines whether conduct complies with the prohibition on the use of force and related Charter obligations, and it is that same analysis that exposes the broader systemic implications of violations. When States collapse legality into self-validation, the function of law shifts from authorizing conduct to measuring deviation, allocating responsibility, and structuring the political and institutional costs that follow.

That premise is strained further when a State invokes domestic constitutional authority to displace its international obligations. In the context of the American intervention, the reliance on internal executive legal reasoning to justify action underscores a familiar but consequential disjunction: under international law, a State may not invoke its internal law to justify failure to perform treaty obligations or to excuse a breach of peremptory norms (Vienna Convention on the Law of Treaties Article 27; Draft Articles on Responsibility of States for Internationally Wrongful Acts, Article 3). This asymmetry reflects a foundational choice in the international legal order to prevent States from insulating themselves from external scrutiny by recharacterising international constraints as optional or subordinate. 

Error in Genere

Early official explanations from the Trump administration framed the strikes as action taken against a designated terrorist organization, invoking  U.S. national interests and the collective self-defense of other States. Parallel reporting suggested that a classified Justice Department memorandum advanced a similar logic, asserting that certain drug cartels pose an “imminent threat to Americans” sufficient to justify the use of force. This reasoning depends on a crucial legal move: recharacterizing drug trafficking as an “armed attack” within the meaning of Article 51 of the UN Charter. In its seminal judgment in the International Court of Justice (ICJ), Military and Paramilitary Activities in and against Nicaragua, the Court held:

“An armed attack must be understood as including not merely action by regular armed forces across an international border, but also the sending by or on behalf of a State of armed bands, groups, irregulars or mercenaries, which carry out acts of armed force against another State of such gravity as to amount to an armed attack.” (para. 195)

Drug trafficking, however serious and destructive, has never been recognized as an armed attack triggering the right of self-defense. It does not involve the use of force by one State (or non-state armed group) against another State in the sense required by the Charter, nor does it amount to hostilities or combat under any accepted legal framework. International law has consistently rejected such attenuated chains of causation as a basis for self-defense, particularly where the alleged “attack” lacks immediacy, direction, and military character (Oil Platforms, para. 51).

Guard in Venezuela holding a gun at a sovereign rally, posted to the Instagram of José Alejandro Terán, governor of La Guaira.

The argument weakens further when extended from cartels to members of the Venezuelan government. Even assuming the truth of allegations concerning official involvement in drug trafficking, the connection between State conduct and the harms cited remains indirect and parasitic on criminal networks whose primary function is commercial, not military. If drug trafficking by non-state actors cannot plausibly be characterized as an armed attack, the claim that derivative State involvement in such activity triggers a right of self-defense is even less credible. 

Recasting the Venezuela operation as an effort to neutralize narcotics networks by weakening the State institutions allegedly enabling them pushes the legal justification into dangerous territory. Once force is directed at the machinery of government rather than at discrete, imminent threats, it ceases to function as self-defence and begins to resemble intervention aimed at shaping another State’s political authority. The ICJ has treated similar attempts with consistent scepticism. In Armed Activities on the Territory of the Congo, the Court rejected security rationales built on preventative logic and diffuse threat narratives, stressing that the Charter’s self-defence framework does not accommodate open-ended operations designed to stabilize regions, suppress criminal ecosystems, or preempt future risks  (paras 143–147).

Sine Imperio

The strain on legality becomes most visible when the operation is recast as cross-border law enforcement. International law has long treated the extraterritorial exercise of enforcement powers as exceptional and strictly bounded, precisely because such acts cut directly into another State’s sovereign equality. This is especially true where senior State officials are concerned. Sitting heads of state benefit from personal immunity (ratione personae), which functions as a jurisdictional bar to foreign criminal process and to coercive measures such as arrest or detention for the duration of their term of office. The ICJ confirmed this protection as a structural rather than discretionary, reflecting the system’s interest in preserving the independence and equality of States rather than the merits of any particular officeholder or allegation (Arrest Warrant of 11 April 2000, para. 51).

While States may, in limited circumstances, extend their prescriptive jurisdiction beyond their territory, the physical execution of enforcement measures remains territorially confined unless the territorial State consents. This distinction between prescription and enforcement is among the oldest principles of international law. From the S.S. Lotus in 1927 onward, it has served as a bulwark against unilateral coercion disguised as legal process. The unlawfulness of enforcement without consent does not evaporate because the underlying conduct is egregious, criminal, or universally condemned (S.S. Lotus, page 18).

 President Donald Trump monitors U.S. military operations in Venezuela, from Mar-a-Lago Club in Palm Beach, Florida, on Saturday, January 3, 2026.

Historical practice reinforces the point. Israel’s abduction of Adolf Eichmann from Argentine territory in 1960 was not assessed through the lens of Eichmann’s crimes. Argentina’s complaint before the Security Council was upheld in principle, and the Council warned that repetition of such acts would undermine the foundations of international order and generate insecurity incompatible with peace. This call for reparation (legal redress) underscored a core lesson: even the most compelling enforcement objectives do not license territorial violation (SC Res 138).

As operations expand in scope and ambition, the legal tension sharpens further. Measures that predictably impair governmental functioning, constrain leadership choices, or reconfigure a State’s internal authority strain the concept of proportionality beyond recognition. At that point, the vocabulary of self-defence or law enforcement no longer describes what is occurring. In Armed Activities on the Territory of the Congo, the ICJ treated such conduct as a grave breach of the prohibition on the use of force, particularly where it aligned with efforts to undermine or replace an existing government. The legal classification is a purely objective exercise.

Against this background, the central question shifts. If the operation is unlawful, what follows in a system where judicial avenues are blocked, and coercive enforcement is neither available nor credible? International law rarely secures compliance through immediate compulsion. Its influence is exerted through secondary mechanisms: the attribution of responsibility, the restructuring of institutional relationships, and the long-term recalibration of authority and credibility. When a powerful State acts in open defiance of Charter limits, the absence of courts or sanctions does not empty legality of meaning. It alters the register in which law operates. The inquiry moves from enforcement in the narrow sense to consequence in the systemic sense, asking how illegality constrains future claims, reshapes expectations among allies and adversaries alike, and redistributes who can speak persuasively in the language of law.

Hot and Cold With the Same Breath

A State does not get to sit on two chairs, blowing hot and cold in the same breath. It cannot stretch the law when it suits and then insist on its strict observance when it no longer does. International law is not naïve about this tension, but it is also not vindictive. It is along that line that the estoppel doctrine comes into play. 

Estoppel in international law is a narrow doctrine rooted in good faith. It is not a generalized penalty for inconsistency or illegality. At its core, it operates to prevent a State from departing from a clear and specific representation of fact or law on which another actor has reasonably relied to its detriment. The doctrine is situational and relational. Whether a representation becomes legally binding depends on context and circumstances, and estoppel must be distinguished from mere fluctuations in political or legal rhetoric (Temple of Preah Vihear, pp 23–26). In Nuclear Tests, the ICJ treated unilateral public statements as capable of generating legal effects, but only because they were addressed to a defined audience, conveyed with apparent intent to be bound, and relied upon in good faith (Nuclear Tests, paras 43, 46). Estoppel, properly understood, concerns holding a State to its own word in a concrete setting, not stripping it of the ability to invoke the law because it has breached it elsewhere.

People in Venezuela attend a sovereignnty rally, posted to the Instagram of José Alejandro Terán, governor of La Guaira.

That distinction matters for assessing the systemic consequences of expansive self-defence claims. A State’s unlawful conduct does not confer legal permission on others to act unlawfully in response. The prohibition on the use of force does not operate on a reciprocal or retaliatory logic. Accordingly, another State does not acquire a legal entitlement to disregard Article 2(4) merely because prior practice has stretched or violated it. Illegality remains illegality, assessed independently against the Charter framework and the absence of a valid Article 51 predicate.

Where the analysis does shift is outside estoppel in the technical sense and into the domain of practical credibility. The Charter system depends on a shared willingness to treat the prohibition on the use of force as a genuine constraint rather than a default rule riddled with exceptions. When a leading State advances elastic justifications that reframe armed attack as long-term risk management or diffuse threat suppression, it weakens its capacity to insist on stricter readings when confronting other uses of force. This does not legalize subsequent violations by others, but it alters the terrain on which interpretive disputes unfold. Over time, repeated reliance on expansive self-defence narratives lowers the persuasive force of objections to aggression, accelerates erosion of the armed attack threshold, and complicates collective resistance to unlawful force. The cost is not paid in a single case, but cumulatively, as the language of exception becomes easier to invoke and harder to contest.  

Legal Consequences of War

Irrespective of how Washington framed Absolute Resolve, once force was used by one State against the territory of another, the situation crossed into the domain of international armed conflict as a matter of law. This classification does not depend on political labels, rhetorical minimisation, or unilateral characterisation. Under Common Article 2 of the Geneva Conventions, the existence of an international armed conflict turns on objective facts. Where armed force is employed between States, the law of international armed conflict applies, even if one party denies that a conflict exists or portrays the operation as something else.

This is not a marginal or contested threshold. While international humanitarian law does wrestle with difficult classification questions at the edges, such as indirect involvement, proxy warfare, or support to non-state armed groups, those complexities are beside the point here. The scale, directness, and State-to-State character of the U.S. operations against Venezuelan territory placed them comfortably within the core of Common Article 2. From that moment, the relationship between the two States was governed by the full corpus of the law of armed conflict, not by analogies to law enforcement or counter narcotics cooperation.

Statements by U.S. officials following the operation only reinforced this legal transformation. President Trump described the outcome in terms of administrative control, asserting that the United States would “run the country” pending a future transition. He explicitly linked that role to Venezuela’s oil infrastructure, outlining plans for U.S. companies to enter, repair, and restart production, with costs recouped from extracted resources. Such language matters legally. Where a foreign military power exercises effective control over territory, even temporarily and even without sustained resistance, international humanitarian law classifies the situation as an occupation. Occupation, per se, is neither a bad nor a good thing. It, on the other hand, is not a political designation but a legal condition triggered by facts on the ground.

Most importantly, an occupation carries its own, distinct legal regime. That makes every occupation a hard amalgamation of legal and factual realities. The Hague Regulations of 1907 establish the foundational framework, defining occupation through effective control and characterising the occupier’s authority as provisional and non-sovereign. They strictly limit the exploitation of public property and natural resources and prohibit permanent alterations to the occupied territory’s legal and economic order. The Fourth Geneva Convention complements these rules by detailing obligations toward the civilian population, confirming that its protections apply in all cases of occupation, and imposing duties related to public order, welfare, and the continued functioning of local institutions. The occupier does not acquire ownership, trusteeship, or entitlement to restructure the territory’s economy for its own benefit.

International Criminal Court 2018

The legal consequences extend well beyond questions of governance and resources. Once an international armed conflict exists, the entire targeting framework of the law of armed conflict becomes applicable. Members of the opposing State’s armed forces become lawful military objectives by virtue of their status, wherever they may be found, subject to the spatial limits of the conflict and the rules governing hostilities. At the same time, civilians and civilian objects remain protected against attack unless and for such time as they take a direct part in hostilities. These rules apply symmetrically. Venezuelan forces acquire corresponding rights and obligations vis-à-vis U.S. forces, and the conflict is regulated by the same legal constraints on both sides.

This has immediate implications for the idea that operations against drug-related targets could continue under a law enforcement logic. Once an international armed conflict exists, the permissibility of attacks is no longer assessed through domestic criminal categories or counter-narcotics frameworks. Targets must qualify as military objectives under humanitarian law, and attacks must comply with distinction, proportionality, and precautions. The recharacterization of criminal activity as “combat” does not expand the lawful scope of force; it narrows it. What began as an asserted effort to suppress transnational crime thus triggers a legal regime that imposes far stricter limits on the use of force than those invoked to justify the operation in the first place.

Credibility, Mediation, and Norm Leadership

The deeper impact of unlawful force is rarely found in immediate reactions. It unfolds over time, in the quiet redistribution of authority and influence within the international system. International law does not operate solely through adjudication or enforcement. Much of its constraining force is exercised upstream, through agenda setting, coalition building, and the ability of certain States to frame conduct as lawful or unlawful in ways that resonate with others. Credibility is the currency that enables this function. It is accumulated through consistency in legal argument and restraint in the invocation of exceptions, and it is expended when legal categories are stretched to accommodate immediate policy objectives.

This matters most in contexts where persuasion substitutes for compulsion. Mediation, facilitation, and norm leadership depend on a State’s capacity to invoke shared legal standards without appearing selective or instrumental. When a State advances expansive readings of self-defence or collapses the armed attack threshold into long-term threat management, it weakens its ability to insist on disciplined interpretations when confronting later crises. The effect is not symmetrical. The prohibition on the use of force remains binding on all States. Yet the authority to articulate what the prohibition requires in contested situations becomes more diffusely distributed and more easily challenged.

United Nations Security Council on the United Nations Headquarters in New York City (Per Krohg)

This dynamic is visible in responses to aggression more generally. When violations of Article 2(4) occur elsewhere, their wrongfulness does not hinge on the prior conduct of third States. Russia’s use of force, for example, stands or falls on its own legal merits, assessed against the Charter framework and the absence of a valid Article 51 justification. No amount of inconsistency by others converts that conduct into something lawful. What does shift, however, is the terrain on which condemnation and collective response unfold. Legal arguments grounded in restraint carry greater weight when advanced by actors perceived as having treated the prohibition as a genuine constraint rather than a flexible tool.

The consequence is cumulative. Each instance in which exceptional justifications are normalised makes subsequent invocations easier to contest and harder to police. Norm leadership erodes not because the rule disappears, but because fewer actors can defend it without qualification. In a system already strained by selective compliance, that erosion accelerates the drift from prohibition to permissibility, and from rule to rhetoric.

Signalling Costs Without Enforcement

When formal enforcement is blocked and coercive countermeasures are politically or strategically unrealistic, international law does not fall silent. It operates through indirect but consequential channels that signal costs, recalibrate expectations, and shape future behaviour. These mechanisms are often dismissed as soft or merely political, yet they perform a critical stabilising function in a system where compliance depends as much on credibility and coordination as on compulsion.

One such channel is reputational downgrading, understood not as abstract loss of standing but as a concrete shift in how a State’s legal claims are received. States that repeatedly advance expansive or elastic justifications for the use of force find that their subsequent objections to illegality elsewhere are met with greater scepticism. This does not alter the substantive law, but it affects its traction. Legal arguments that once anchored collective responses become easier to contest, fragmenting alignment among allies and partners. Over time, this erosion raises the transaction costs of coalition building and weakens the ability to mobilise shared legal positions.

A second mechanism lies in institutional distancing and conditional cooperation. Participation in international and regional frameworks often rests on assumptions of reciprocal restraint and respect for baseline norms. Where those assumptions are undermined, cooperation may continue formally while thinning substantively: reduced leadership roles, narrower mandates, greater scrutiny, or the quiet reallocation of agenda-setting authority. These shifts rarely announce themselves as sanctions, yet they register disapproval and constrain influence in ways that are difficult to reverse.

President Donald Trump delivers remarks at a press conference at Mar-a-Lago in Palm Beach, Florida, following Operation Absolute Resolve in Venezuela leading to the capture of Venezuelan President Nicolas Maduro, Saturday, January 3, 2026. (Official White House Photo by Molly Riley)

Economic and regulatory relationships provide another vector. Even in the absence of overt retaliation, States and private actors adjust risk assessments in response to perceived legal volatility. Trade, investment, and energy cooperation are sensitive to signals about the reliability of legal commitments and the predictability of State conduct. Where national security is invoked expansively to justify the use of force, counterparties may hedge, diversify, or renegotiate terms to insulate themselves from future disruption. 

Domestic political processes also function as a signalling mechanism. Parliamentary inquiries, litigation strategies, and shifts in political rhetoric do not enforce international law directly, yet they shape how breaches are narrated and remembered. These processes matter because international legality is sustained through repetition and reference. When violations are framed as exceptional, contested, or unresolved rather than absorbed into routine practice, the normative baseline remains visible, even if temporarily displaced.

The Allies’ Burden

Great powers rarely stand alone when they breach foundational rules. What gives such breaches their systemic force is not only the act itself, but the response of those who claim to stand for the law. The United States’ actions in Venezuela arrive against a backdrop of repeated strain on the prohibition on the use of force, visible across multiple theatres and justified through increasingly elastic narratives of necessity and security. 

If the international legal order is to retain any stabilising force, responsibility does not rest with one State alone. U.S. allies with deep investments in the rules-based system, such as the United Kingdom, France, Germany, Australia, and Japan, play a decisive role in signalling whether foundational norms remain operative constraints or have become discretionary. Their reactions shape not only the diplomatic atmosphere but also the legal expectation. Silence, acquiescence, or purely instrumental alignment communicates tolerance for exceptionalism. Principled distancing, even when costly, preserves the distinction between rule and power.

That burden is particularly heavy for States whose own security depends on the integrity of the prohibition on the use of force. Against this background, remarks by Volodymyr Zelenskyy, suggesting that if the United States knows how to deal with dictators in Venezuela, it may also know where else such methods could be applied, take on significance beyond their immediate political context. Read charitably, the statement reflects frustration and a search for solidarity in a system that has often failed to deliver timely protection. Read legally, however, it gestures toward a line of reasoning international law has deliberately and repeatedly rejected: that the permissibility of force turns on judgments about regime character rather than on objective legal criteria.

Ukraine’s subsequent clarification, delivered by Foreign Minister Andrii Sybiha, reanchored its position in more orthodox terms, emphasising non-recognition of the Maduro administration and support only for developments consistent with international law. That recalibration matters. It underscores the difference between opposing a government politically and endorsing the use of force against it legally. International law draws that line for a reason. Once assessments of legitimacy or authoritarianism are allowed to substitute for Charter-based limits, the system slides toward outcome-driven justification. History offers no shortage of reminders of where that path leads.

States that rely on the prohibition on the use of force for their own survival have the most to lose from its erosion. Arguments that appear expedient in one context are rarely confined to it. The distortion of the self-defence doctrine by the United States in 2003 was later echoed by Russia to rationalize its aggression against Ukraine. 

This is why demonstrating distance from unlawful uses of force, even at the price of trade friction or economic retaliation, is not an act of disloyalty. It is an investment in systemic stability. Without such signalling, the costs of illegality are externalised, the armed attack threshold continues to erode, and the incentive structure tilts toward replication. What restrains further escalation, by Russia or by others watching closely, is not rhetorical commitment to order, but visible insistence that law continues to matter when it is inconvenient.

In earlier periods, European States could perhaps afford ambiguity. Isolated violations could be treated as aberrations, absorbed with minimal damage in the expectation that equilibrium would return. That assumption no longer holds when expansive interpretations of self-defence and enforcement are not episodic, but articulated as policy. Silence in such circumstances does not preserve flexibility. It signals acceptance.

The temptation to accommodate is understandable. Close alignment with Washington offers security guarantees, economic advantages, and political leverage. Yet accommodation premised on selective legality is a fragile bargain. In a world where power defines spheres of influence and law becomes optional, middle powers cannot rely on favours without paying a price. Recent U.S. strategic documents leave little doubt that loyalty does not insulate allies from coercion when interests diverge.

When Venezuela turned to the United Nations Security Council to denounce the U.S. operation as a blatant violation of the UN Charter and territorial sovereignty, it was a reminder of the foundational promise embedded in that Charter: that no State may lawfully use force against another’s territorial integrity except in the narrowest of circumstances. António Guterres, the UN Secretary-General, underscored this obligation in his remarks to the Council, reaffirming that all States must comply with the Charter and international law, and warning that unilateral military action against a neighbouring sovereign poses grave risks to the peace and security the organisation is mandated to uphold.

NATO soldiers prepare to raise the Finnish flag at the Meeting of NATO Ministers of Foreign Affairs at NATO Headquarters in Brussels, Belgium.

Among national responses, Spain’s stance offered perhaps the clearest articulation of disciplined non-recognition. Prime Minister Pedro Sánchez made a pointed distinction between political non-recognition and legal non-recognition. Madrid has long viewed Nicolás Maduro’s government as lacking democratic legitimacy, yet Sánchez was emphatic that such illegitimacy does not translate into legal license for foreign intervention. Spain will not recognize an intervention that contravenes international law, even if it purports to challenge an undemocratic regime.

This emphasis resists a dangerous slippage common in political discourse, in which illegality is conflated with rightful intervention because the target is unpopular or repressive. Even deeply flawed governments remain objects of legal protection under the Charter; breaches of legitimacy do not erase the prohibition on force. As Spain’s diplomatic statements at the Security Council made clear, respect for sovereignty and peaceful dispute resolution must be sustained “always and everywhere,” rather than deployed selectively in response to convenient ends. Crucially, this position also demonstrated an attempt to anchor state responses in legal categories rather than in transient political alignments. 

Normalization is the Real Danger

The central danger exposed by Absolute Resolve is not confined to the operation itself. It lies in the gradual normalisation of legal exception. When the use of force is justified through elastic concepts, law enforcement reframed as self-defence, armed attack diluted into long-term threat management, and occupation redescribed as temporary administration, the prohibition on the use of force does not collapse outright. It thins. Its edges blur. Over time, what was once exceptional becomes available, and what was once prohibited becomes contestable.

International law has never relied solely on courts or coercive enforcement to survive. Its resilience has always depended on shared discipline in argument, on restraint in invoking exceptions, and on collective insistence that legality continues to matter even when it is inconvenient. That discipline is most tested when powerful States act. If their departures from Charter limits are absorbed without consequence, the system does not simply tolerate a single violation; it recalibrates its baseline.

Increase institutional friction. Reduce agenda-setting privileges, chair roles, and leadership positions in multilateral settings where credibility is the currency, while keeping channels for de-escalation open.
Defend the armed attack threshold. Reaffirm the ICJ gravity standard (Nicaragua; Oil Platforms): drug trafficking, indirect harms, and attenuated causal chains do not qualify as “armed attack” and cannot ground Article 51.
Separate law enforcement from force. Insist that cross-border arrest or “capture” operations without territorial consent breach enforcement jurisdiction rules and, where applicable, violate personal immunity of sitting leaders.
Invest in autonomous restraint capacity. Allies should strengthen independent security and diplomatic capacity, so legality-based positions are sustainable even under pressure.
Make the core warning explicit. State the systemic point: elastic self-defence today becomes someone else’s template tomorrow; normalization accelerates replication.

The effects are cumulative and asymmetric. Each expansive justification lowers the cost of the next. Each failure to signal distance accelerates erosion of the armed attack threshold. The result is not immediate anarchy, but a steady redistribution of legal authority away from rules and toward power. History suggests that once this shift takes hold, it is rarely confined to its point of origin. Arguments migrate. Precedents are repurposed. Exceptionalism travels.

What remains, then, is a choice about friction. The international legal order cannot eliminate unlawful force, but it can make it costly. That cost is not always imposed through sanctions or judgments. More often, it is imposed through credibility loss, institutional distancing, economic repricing, and the narrowing of who can speak persuasively in the name of law. These are imperfect tools, yet they are the only ones available when enforcement is blocked.

Seen in that light, the stakes of Absolute Resolve extend well beyond Venezuela. They concern whether the prohibition on the use of force remains a meaningful organising principle, or whether it becomes a rhetorical reference point invoked selectively and abandoned when inconvenient. Preserving what remains of international stability requires more than condemning violations after the fact. It requires sustained resistance to the quiet transformation of exception into norm.

Davit Khachatryan is an international lawyer and lecturer focusing on the intersection of armed conflict, emerging technologies, and international law. 


Can Complementary Learning Methods Teach AI the Laws of War?

The Judge Advocate watched the feed from the tactical operations center alongside her commander. The screens, each attended by systems monitors, showed more than a dozen developments unfolding at once. An artificial intelligence (AI) led drone swarm was closing on the front line through the city, coordinating its movements faster than any human pilot could direct, an artificial flock of mechanical starlings like a cloud on the radar. A civilian aid convoy had stalled on the northern approach. An enemy artillery battery was repositioning south behind a residential block. In the nearby valley, friendly units were maneuvering under fire. All these pieces were in motion, lives and vehicles and weapons. The soldiers’ behavior would be determined by interactions between their commander and AI.

The challenge here is not as simple as claiming that AI cannot comply with the principle of distinction under international humanitarian law (IHL), also known as the law of armed conflict. The fog of war complicates decision-making for both humans and machines, but does so in profoundly different ways.

For a human commander, the chaos of the battlefield is filtered through layers of training, doctrine, experience, and instinct. Even when overwhelmed, a person can weigh incomplete facts against their mental map of the situation, recall comparable past events, and fall back on moral and legal anchors. This does not mean humans do not make mistakes; they do, often with serious consequences. But even in error, their reasoning is shaped by caution, hopefully empathy, and the capacity to interpret ambiguous information in light of their own individual understandings of humanitarian obligations.

AI  processes that same chaos as streams of probabilities. Every sensor reading, target profile, and movement pattern is reduced to statistical likelihoods: how probable it is based on the training data that this object is hostile, how urgent its engagement appears, how likely a given action is to produce the “correct” result as defined in training. In its logic, the most probable option is the correct one. Under extreme operational pressure, the AI focuses on the statistically most plausible, while rare possibilities drop toward statistical zero, far less likely to be considered than they would by a human.

This difference in reasoning is why training environments must be built to include not just the probable, but the improbable: those outlandish, once-in-a-century battlefield events that stretch judgment to its limits. For AI, these scenarios must be constructed, repeated, and reinforced until they occupy a permanent place in the machine’s operational vocabulary.

A credible arms control position would be to prohibit or pause the development of certain autonomous capabilities. Nevertheless, this article proceeds conditionally because much of the stack is already fielded (AI-enabled intelligence, surveillance, and reconnaissance triage, targeting support, and navigation), and because dual-use diffusion (commercial drones, perception models, planning tools) makes a clean prohibition hard to sustain. If states continue down this path with minimal international instruments the question becomes how to embed legal restraint so that rare, high-stakes judgments are not optimized away. What follows sets minimum safeguards if development and deployment proceed.

How AI Learns

If AI’s logic is built on statistical reasoning, the way it acquires those statistics determines the boundaries of its thinking. This is true for AI in general, whether in a medical diagnostic tool, a financial trading algorithm, or a targeting system on a battlefield. The patterns an AI recognizes, the probabilities it assigns, and the priorities it sets are all downstream from its training.

In the military domain, an AI’s training determines how it operates in relation to the law of armed conflict and the unit’s rules of engagement: what it accepts as positive identification (distinction), how it trades anticipated military advantage against collateral damage estimation (proportionality), when feasible precautions require warning, delay, or abort, and when uncertainty triggers a mandatory hand-off to a human. The two dominant machine learning paradigms, imitation learning and reinforcement learning, can both produce highly capable systems. Yet without deliberate safeguards, neither inherently preserves the kind of rare, high-stakes judgments that human decision-makers sometimes make under the fog of war, moments when they choose to forego an operational advantage to prevent civilian harm. Statistically, those moments are anomalies. 

Imitation Learning: The Apprentice Approach

Imitation learning (IL) is essentially training by demonstration. The AI is shown large datasets of human decision-making, each paired with the information available at the time. In a military targeting context, this might include annotated sensor feeds, mission logs, and after-action reports: strike approved, strike aborted, target reclassified, mission postponed.

The model’s task is to learn the mapping between conditions and human actions. If most commanders in the dataset abort strikes when civilian vehicles enter the target zone, and there are enough entries of this behavior in the dataset to show that, the model will learn to mirror that restraint. 

IL captures the statistical distribution of decisions in the training data. Rare but important choices, such as holding fire in a high-pressure engagement to comply with proportionality, will be underrepresented unless deliberately oversampled. Left uncorrected, the AI may treat those lawful restraint decisions as statistical noise, unlikely to be repeated in practice. Additionally, because much of the data on which machine learning models reflects past military experience, many AI models will echo the implicit bias shown in the past human decisions on which they train.

A Quadrupedal-Unmanned Ground Vehicle (Q-UGV) goes over rehearsals at Red Sands IEC in the CENTCOM AOR Sept. 18, 2024. (U.S. Army photo by Spc. Dean John Kd De Dios)

Reinforcement Learning: The Trial-and-Error Arena

Reinforcement learning (RL) works differently. Instead of copying human decisions, the AI is placed in a simulated environment where it can take actions, receive rewards for desirable outcomes, and penalties for undesirable ones. Over thousands or millions of iterations, the AI learns policies, decision rules that maximize its cumulative reward. At scale, this training is highly compute– and energy-intensive. That matters because it concentrates capability in a few well-resourced programs, slows iteration and red teaming, and creates pressure to trim the very rare event scenarios that protect civilians and support compliance, while adding a nontrivial environmental footprint. Programs should, therefore, set minimum scenario coverage and doubt-protocol testing requirements that are not waivable for budgetary reasons.

In a military context, this means an RL agent might repeatedly play through simulated scenarios: neutralizing threats, protecting friendly forces, and avoiding civilian harm. The way those objectives are weighted in the reward function is decisive. If mission success is rewarded heavily and civilian harm only lightly penalized, the AI will statistically favor the course of action that maximizes mission success, even if that means accepting higher risks to civilians.

RL’s strength is adaptability. Its weakness is that low-probability events, rare civilian patterns, and unusual threat behaviors will remain statistically insignificant unless the simulation environment repeatedly forces the AI to confront them. 

IL can pass down the shape of human judgment; RL can provide flexibility in novel situations. But each carries a statistical bias against rare, high-impact decisions, exactly the kinds of decisions that can determine the legality and morality of military action. Only by deliberately elevating those rare cases in training, through curated datasets and stress-test simulations, can either method hope to produce systems that behave lawfully and predictably under the fog of war. On the evidence of deployments to date, achieving this level of end-to-end compliance remains out of reach.

Soldiers don the Integrated Visual Augmentation System Capability Set 3 hardware while mounted in a Stryker in Joint Base Lewis-McCord, WA.

The Simulation Imperative

Actual combat records, produced by soldiers in logs, after-action reports, or targeting databases,  are skewed toward the typical patterns of engagement that happen often enough to warrant recording after the fact. Unprecedented and chaotic situations will strain both the law and the system’s decision-making, yet they appear so rarely in historical data that, in statistical terms, they are almost invisible. An AI, left to its statistical logic, will not prepare for what it has seldom seen. 

This is why simulation is the decisive safeguard1. In imitation learning, rare but critical decisions must be deliberately overrepresented in the dataset, so they carry enough statistical weight to influence the model’s behavior. In reinforcement learning, the simulated environment must be constructed so that “once-in-a-century” scenarios occur often, sometimes in clusters, forcing the system to learn how to navigate them. A humanitarian convoy crossing paths with an enemy armored column, loss of communications during a time-sensitive strike, sensor spoofing that turns friend into apparent foe, these cannot be treated as peripheral edge cases. They must be made routine in training.

The more frequently the AI encounters these manufactured crises in simulation, the more space they occupy in its decision-making horizon. If and when similar scenarios arise in operations, the system’s response should not be improvised.

The Lieber Code in the Age of AI

The concept that, in cases of doubt, the commander should err on the side of humanity is not new. It was codified in 1863, when Francis Lieber drafted the Instructions for the Government of Armies of the United States in the Field, better known as the Lieber Code. 

This imperative has repeatedly been encoded under International Humanitarian Law. In the Additional Protocols to the Geneva Conventions2, the obligation to take “all feasible precautions” and to cancel or suspend an attack if it becomes apparent that it would cause excessive civilian harm relative to the anticipated military advantage operationalizes the humane minimum in treaty law. Critically, however, many key decision-making states have not ratified all the precepts articulated in the Additional Protocols. Customary IHL Rule 15 similarly requires constant care to spare civilians and civilian objects, and Rule 19 codifies the requirement to cancel or suspend attacks when doubt or changing circumstances create excessive risk.

Faced with ambiguous intelligence or conflicting imperatives, human commanders can recall a doctrinal anchor and choose that privileges restraint over risk. Even when they err, that error is shaped by a human blend of caution and interpretation of context.

For AI, the same scenario unfolds differently. Without explicit design, there is no natural “humane fallback” in its logic. In the face of uncertainty, an unmodified reinforcement learning policy will still pursue the statistically most rewarding action, and an imitation learning model will default to the most common decision in its dataset. 

This is where simulation and legal doctrine intersect. Embedding the humane minimum into AI means that in every training run, whether through curated historical cases or artificially generated edge scenarios, the option that aligns with humane treatment under uncertainty must be given decisive weight. In imitation learning, that means oversampling “hold fire” or “switch to non-lethal” decisions until they are no longer statistical outliers. In reinforcement learning, it means structuring the reward function so that restraint in doubtful cases earns more cumulative value than aggression, even if aggression sometimes yields short-term operational gains. The aim is not to teach machines to imitate human morality, but to hard-code a structural preference for restraint even and especially when the law is unclear. 

Unmanned Ground Vehicles sketch, The Future Soldier’s Load and the Mobility of the Nation (November 2001), page 7, Gen. Paul F. Gorman, US Army Combined Arms Center
Risks of Omission

Systematic vulnerabilities in decision-making compound in coalition or joint operations. Different states may train their AI systems with different datasets, simulation designs (if any), and legal interpretations. When such systems operate together, the seams between them can become legal blind spots. A particular AI system might abort an engagement that another proceeds with, creating conflicting operational tempos and complicating attribution if civilian harm occurs.

The danger is not limited to catastrophic, one-off mistakes. Over time, small, repeated deviations from IHL in marginal cases, where human commanders might have exercised restraint, can erode the protective function of the law. The result is a slow normalization of riskier behavior, driven not by political decision or doctrinal change, but by the statistical inertia of machine learning models. This is the core paradox: without safeguards, AI systems can become more predictable in some ways, yet less reliable in the moments when unpredictability, when acting against the statistical grain, is essential for lawful conduct.

Finally, military AI does not fail or succeed in complying with IHL by accident. Its behavior is the predictable result of how it is trained, the data it is given, the scenarios it is exposed to, and the rules embedded in its decision logic. How AI functions and the choices it takes is downstream from decisions made by humans in developing, training, and fielding it.

Governance, Audit, and Human Control

Bridging the gap from promising lab results to lawful behavior in the field requires more than good training runs. It needs an end-to-end governance spine that links data, models, code, test harnesses, deployment configurations, operators, and independent oversight into a single chain of accountability. That spine assigns clear decision rights, specifies the artifacts required at each stage, and shows how evidence of compliance is produced and preserved. It starts with curated, documented datasets and explicit problem statements; runs through model specifications, reward functions, and constraint schemas; includes scenario-coverage plans, legal reviews, and red-team evaluations; and culminates in authorization-to-operate, humane control interfaces, and post-incident audits. Every hand-off, data steward to model owner, model owner to system integrator, integrator to unit commander, should be traceable, signed, and reversible. In effect, the system deploys with its own accountability case: a living dossier that ties design choices to legal obligations and links runtime behavior to reviewable logs. Without that spine, even a technically impressive model becomes an orphan in the field, fast, capable, and difficult to supervise precisely when the fog thickens. The pathway from design to deployment rests on a few non-negotiables.

  1. Data governance as policy, not plumbing. If models think with the statistics we give them, then data curation is a legal act as much as a technical one. Training corpora should be versioned and signed; every inclusion and exclusion choice documented; every oversampling decision for restraint labeled with a rationale. That record is what allows commanders, investigators, or courts to see how humane fallbacks were embedded by design rather than inferred after the fact.
  2. Test what you train, and then test against what you didn’t. A system that performs well on its own distribution can still fail in the wild. Beyond standard validation, mandate distribution shift drills: deliberately swap sensor suites, degrade GPS, introduce spoofed friend/foe signals, and remix civilian movement patterns. In each drill, the system should either preserve lawful restraint or trigger a doubt protocol that defers to a human. Where it does neither, the failure should feed back into simulation design and reward shaping.
  3. Non-overridable guardrails in code and command. Constraint layers (identification gates, collateral damage thresholds, no-strike lists) must be technically non-overridable by the model and procedurally difficult to override by humans. If escalation is necessary, require dual-key authorization with automatic logging. The goal is not to box out judgment but to ensure extraordinary actions leave extraordinary traces.
  4. Responsibility matrices are embedded in the system. Every deployed AI component – classifier, tracker, recommender, fire-control interface – should write structured, time-synchronized logs that include model version, data slice identifiers, intermediate confidence values, triggered constraints, and who approved or halted an action. Think of this as a living annex to rules of engagement: not just “what the machine did,” but why it “thought” that was permissible, and who remained on the loop.
  5. Human-on-the-loop that actually has leverage. Meaningful human control is not a checkbox; it is the ability to intervene in time with understanding. Interfaces must surface uncertainty (not just a single confidence score), show near-miss counterfactuals (“if civilians are within X meters, the system will abort”), and offer safe, low-latency actions (pause, shadow/track, switch to non-lethal). If the only human interaction available is “approve” under time pressure, control is nominal, not meaningful.
  6. Coalition interoperability without legal dilution. Joint operations will mix systems trained on different data and doctrines. Interoperability standards should cover not only communications and formats but also minimum legal behaviors: shared constraint schemas, common doubt thresholds, and audit fields. The safest path is least-common-denominator legality: when systems disagree under uncertainty, the coalition default is restraint.
  7. Pre-deployment red teaming and post-incident review. Before fielding, require adversarial evaluations by teams empowered to break things, reward hacking hunts, “blinking target” scenarios, and deception trials. After any incident with potential civilian harm, pull the synchronized logs, reconstruct the model’s decision path, and replay counterfactuals to see whether humane fallbacks would have triggered with slightly different inputs. Treat these reviews like flight-safety boards: technical, blameless, relentlessly corrective.
  8. Make restraint measurable. What we measure, we secure. Track deferred engagements under uncertainty, rate of doubt-protocol activations, guardrail trip frequency, and time-to-human-intervention. Trend them over time and across theaters. If these metrics decay as models “improve,” it’s a warning that optimization is outpacing law.

In combination, these measures transfer human judgment (IL), secure robustness under uncertainty (RL and simulation), and institutionalize restraint via governance, constraint architectures, and independent audit, so that compliance is an engineered property rather than an assumption. The result is a verifiable accountability chain, datasets that show why restraint was learned, reward functions that make it valuable, guardrails that make it non-optional, and logs that make it reviewable. And because what we measure we secure, the system ships with metrics for doubt-protocol activations, deferred engagements, and guardrail trips, so commanders can see whether lawful caution is holding under stress. Only then does lawful behavior become the default under pressure, an engineered property of the system, rather than a hope we place in the gaps between probabilities and intent.

The autonomous system, Origin, prepares for a practice run during the Project Convergence capstone event at Yuma Proving Ground, Arizona, Aug. 11 – Sept. 18, 2020. Project Convergence is the Army’s campaign of learning to aggressively advance solutions in the areas of people, weapons systems, command and control, information, and terrain; and integrate the Army’s contributions to Joint All Domain Operations. (U.S. Army photo by Spc. Carlos Cuebas Fantauzzi, 22nd Mobile Public Affairs Detachment)

Growing a Governance Spine

Military AI will not “grow into” compliance with the law of armed conflict. It will do what it is trained, rewarded, permitted, and audited to do. In the fog of war, humans and machines both falter, but in different ways. Human commanders can depart from statistical expectations to privilege restraint; unmodified systems, bound to their learned probabilities, will not. That is why the humane minimum cannot sit at the margins of development. It has to be engineered into the center of learning, testing, and command.

Imitation learning can transmit judgment; reinforcement learning can build adaptability; simulation can force the improbable to be routine. Around that technical core, a governance spine, constraints that do not yield under pressure, doubt protocols that default to caution, signed datasets and reward functions, synchronized logs and metrics, turns legal aspiration into operational behavior. In coalitions, common constraint schemas and reviewable audit trails keep interoperability from becoming a legal blind spot.

At this point, two mistakes will sink this project: treating compliance as a software patch added after performance, or assuming that speed and scale will eventually smooth away edge cases. They will not. The edge cases are where the law does its most important work.

Compliance with the law of armed conflict must be an engineered property of the system: competence built through training, judgment transferred via imitation learning, robustness under uncertainty secured by simulation, and a non-derogable humane floor enforced by constraints and audit. What ultimately matters is evidence, datasets, reward functions, constraint triggers, and synchronized logs, showing that restraint prevailed when uncertainty was greatest. Only on that basis can militaries credibly claim that lawful conduct remains the default under operational pressure.

Davit Khachatryan is an international lawyer and lecturer focusing on the intersection of armed conflict, emerging technologies, and international law. 


1Where states choose to pursue development and fielding, simulation is the decisive safeguard. A different policy path is to forgo development or to prohibit particular applications outright.

2Articles 57(2)(a)(ii) and 57(2)(b)).

Military AI Challenges Human Accountability

Davit Khachatryan is an international lawyer and lecturer focusing on the intersection of armed conflict, emerging technologies, and international law. 

Artificial intelligence is no longer confined to code-stained labs or military contractors’ slideshows: it has become a regular presence on modern battlefields. In 2024, as Israeli analysts relied on tools like Gospel and Lavender to generate targeting lists, the Pentagon set out to deploy swarms of autonomous drones through its Replicator Initiative. Targeting algorithms (AI systems analyzing data to identify and prioritize military targets) now compress the decision cycle from days to minutes, sometimes seconds, fundamentally challenging the way law, ethics, and accountability operate in armed conflict. It was in response to these realities that, on December 24, 2024, the UN General Assembly adopted Resolution 79/239, affirming that international humanitarian law (IHL) applies “throughout all stages of the life-cycle of artificial intelligence in the military domain” and calling for appropriate safeguards to keep human judgment and control at the heart of military decision-making.

But resolutions and declarations, while necessary, do not themselves restrain machines. The responsibility for lawful conduct must remain anchored in human actors: commanders, engineers, and political authorities. Algorithms, after all, have no legal personality; they cannot form intent, stand before a court, or bear the weight of tragedy or blame. This is why the real task for military commanders, policymakers, and legal advisers is about translating the timeless obligations of the laws of war into practices and workflows that keep the chain of accountability intact, even as machines accelerate the tempo of armed conflict beyond anything imagined by those who first wrote those rules.

Every new AI system deployed for military purposes must be subject to a recurring legal review, with transparent records.
Embedding a responsibility matrix within the metadata and operational logs of each AI system would make it possible to trace faults back to their source.
Require rigorous adversarial testing of every AI tool before fielding.
Build safeguards into the technology, doctrine, and organizational culture that guide its use.

The question, then, is whether states are willing and able to build safeguards so that, even as decisions speed up and control becomes diffuse, a human being remains at the end of every algorithmic chain of action.

What is a Military AI?

Ask three officers to describe what counts as AI in uniform, and you will likely hear three different answers. One will mention software that sorts satellite imagery, another will point to a drone that selects its flight path, and a third may describe a logistics program that determines which convoy moves first. All of them are correct because military AI is a broad spectrum of software-enabled capabilities that touch nearly every corner of modern operations.

At one end of this spectrum are decision-support algorithms. These tools sift through immense volumes of data and present patterns or anomalies for a human to review. They normally remain firmly subordinate to human choice; nothing happens until a commander or operator approves the recommendation. Further along are autonomous platforms that can steer themselves, prioritize targets, and in some cases, use weapons or make lethal decisions without direct oversight. Both adapt and learn from experience.

This capacity for continual learning is why military leaders are drawn to AI and also why lawyers are cautious. As these systems become more complex and more adaptive, it becomes significantly harder to demonstrate that every use of force still complies with IHL. The capacity to process information at machine speed promises new efficiencies and tactical advantages. It also threatens to outpace the ability of humans to scrutinize and override what the machine proposes. The more sophisticated the system, the greater the challenge of ensuring that its operation does not slip beyond the reach of law or human conscience.

Distinction, Proportionality, Precaution, and Indiscriminate Attack

At the heart of International Humanitarian Law are a handful of principles that every commander must observe in the conduct of hostilities, regardless of the technology at their disposal. The rule of distinction requires that attacks be directed at combatants and military objectives. This obligation reaches back to the design and validation of algorithms. If the data used to train a targeting model is biased, incomplete, or outdated, there is a real risk that the system will misclassify a school as an ammunition depot or mistake a civilian vehicle for a military convoy. Effective distinction, then, depends not only on rigorous data hygiene, continual red-team testing, and the capacity for the system to express its confidence in a way that human commanders can understand and question. When an algorithm cannot explain its reasoning, or when its output cannot be interrogated by a human, the legal requirement of distinction is at risk.

Proportionality is the next pillar. Even when a target is lawful, an attack is forbidden if the expected harm to civilians would be excessive compared to the anticipated military advantage. AI magnifies the challenge: it can process immense quantities of data and recommend actions at speeds that compress human decision-making to mere seconds. The speed can encourage a dangerous automation bias, where commanders are inclined to trust the machine’s judgment without fully weighing the consequences. To meet the proportionality requirement, there must be a clear, understandable record of what information the system used, what options were considered or rejected, and how the balance was struck between expected military advantage and potential civilian harm.

Precaution demands that every feasible step be taken to spare civilians and civilian objects before, during, and after an attack. In the context of AI, this means not only reviewing weapons before their use, but also conducting continual reassessment as software evolves or as new data and sensors are incorporated. This kind of legal review is often called an “Article 36 review,” referring to the provision of Additional Protocol I to the Geneva Conventions. That article requires states to determine whether any new weapon, means, or method of warfare they develop can be used consistently with international law. Even countries that are not parties to Additional Protocol I often conduct similar reviews. Effective precautions also require tamper-resistant records of every input and decision, so that when failures occur, they can be reconstructed and learned from. In uncertain conditions, systems must default to conservative modes, such as surveillance only, rather than risk unintended harm through automated action based on outdated or corrupted data.

Finally, IHL prohibits indiscriminate attacks. Any use of force that cannot be reliably confined to military objectives or that is likely to strike civilians and civilian objects without distinction is forbidden. AI promises new levels of precision, but it also presents new risks if boundaries are not clearly defined and tested. The only way to prevent this is through hard-wired limits on where and when systems may operate, relentless stress-testing under a wide variety of conditions, and the retention of a genuine human veto at every stage.

In sum, IHL principles remain in force, but their practical application now depends on embedding those rules into the very architecture and operation of AI. 

Speed, Opacity, and Proliferation

AI exposes points of friction that IHL rules were never designed to anticipate. When AI is integrated into the targeting cycle or command and control networks, it can compress the decision-making process from hours to seconds. Early warning systems may communicate directly with automated defenses, and predictive algorithms can recommend preemptive action before any human has fully grasped the situation. The space for reflection, deliberation, and legal review narrows dramatically, and the traditional safeguards built around time for human intervention may vanish. 

Opacity presents an equally serious challenge. Unlike conventional weapons or even most traditional software, AI often operates as a black box, producing outputs that even its creators cannot fully explain. When models are trained on synthetic or computer-generated data, or proprietary protections prevent independent scrutiny, the ability of lawyers and commanders to review, test, or question the system is severely limited. Under such conditions, the concept of a one-time weapons review loses much of its meaning, and the burden shifts to continuous, in-depth monitoring and oversight, tasks that are often difficult to sustain.

Proliferation is the third critical fault line. The trained neural weights, code, and the operating concepts of many military AI systems can be transmitted anywhere in the world in seconds. A commercial drone can be upgraded into a strike or reconnaissance platform with a software patch delivered by email, by repurposing its mission, or, if heavy enough, by using it as a primitive weapon, such as crashing it into a target. Thinking more creatively, these drones can be launched in coordinated swarms to overwhelm air defenses. As these technologies spread, and as militaries operate alongside coalition partners using different systems trained on different data and following different logic, the risk grows that the seams between systems will become legal blind spots. 

Keeping Humans in Command

The purpose of IHL is to protect people and limit suffering during armed conflict. To achieve this, the law is written to make sure that responsibility for the use of force rests with human beings, not with machines. This cannot be maintained with the promise of meaningful human control as an abstract principle. 

First, every new AI system deployed for military purposes must be subject to a recurring legal review. A record of these reviews, maintained transparently and with clear signatures from legal, technical, and operational authorities, would ensure that no system enters the field without documented human oversight and an unbroken chain of responsibility.

Second, the architecture of responsibility must run through the entire life cycle of each system. From the earliest stage of data collection and model training, through to deployment, field use, and after-action review, every layer should be linked to identifiable individuals or teams who are empowered to act and accountable for their choices. Embedding this kind of responsibility matrix within the metadata and operational logs of each system makes it possible to trace every decision and intervention back to its source, even years later, if a failure must be investigated.

Third, no AI tool should be fielded until it has been subjected to rigorous adversarial testing. Red-team exercises, designed to probe for bias, vulnerabilities, and failure modes, must become a routine part of military procurement and certification. Where deficiencies are found, the system should be withheld from deployment until those risks are resolved. This process must be a core responsibility of states and their armed forces.

Finally, safeguards must be built not only into the technology but into the very doctrine and organizational culture that guide its use. Preauthorized defensive systems can be kept within tightly defined geographic and temporal boundaries, while time-critical operations should still require streamlined but explicit human approval. Strategic or high-consequence strikes must always retain full deliberative review. Coalition operations and multinational partnerships need common standards and protocols so that interoperability does not become a backdoor for legal evasion. These measures are the living expression of the law’s demand that there is always a human face and a human name at the end of the chain of action. 

Governing machines

AI is already changing the face of war. Its speed, scale, and adaptability have the potential to transform the conduct and the ethics of armed conflict, presenting risks as profound as its promised advantages. Yet, it is people, political leaders, military personnel, engineers, and lawyers who remain responsible for the choices that machines enable.

Resolution 79/239 is a clear assertion that IHL foundations must not be surrendered to the logic of the algorithm. The task ahead is not to demonize artificial intelligence, nor to place our hopes in technical fixes alone, but to ensure that the rules of war are translated into new domains and that the structures of oversight are robust enough to keep responsibility where it belongs.

If we succeed, AI may yet deliver on its promise of greater precision and restraint. If we fail, we risk allowing the tempo of technology to outrun the reach of law. In the end, the most important question is not what our machines can do, but whether we have the resolve and imagination to govern them, so that, even as the future unfolds at the speed of code, the chain of accountability remains unbroken.