EVR-0011 · CANONICAL /DOCS REPORT

Technical and Regulatory Architecture for the KillWebs.com Law, Authority, and Strategic Stability Lab: Cicero Facility Implementation

Technical and Regulatory Architecture for the KillWebs.com Law, Authority, and Strategic Stability Lab: Cicero Facility Implementation The rapid integration of Lethal Autonomous Weapon Systems LAWS and artificial intelligence-enabled decision-support systems into modern military arsenals represents a profound shift in the application of military force. The compression of time between observation and action—once measured in hours or minutes, and now occurring at machine speed—challenges traditional legal frameworks built upon human deliberation, attribution, and judgment1. Any governance framework designed to manage this transition must securely anchor technological capabi

SHA-2562ff855aa31982656147830521c8d252c325362bb75c9a20189598978370854a7Canonical filedocs/reports/laws-governance-platform-research.md.uai memory.uai/reports/laws-governance-platform-research.uaiOpen raw Markdown

Technical and Regulatory Architecture for the KillWebs.com Law, Authority, and Strategic Stability Lab: Cicero Facility Implementation

The rapid integration of Lethal Autonomous Weapon Systems (LAWS) and artificial intelligence-enabled decision-support systems into modern military arsenals represents a profound shift in the application of military force. The compression of time between observation and action—once measured in hours or minutes, and now occurring at machine speed—challenges traditional legal frameworks built upon human deliberation, attribution, and judgment1. Any governance framework designed to manage this transition must securely anchor technological capabilities to existing International Humanitarian Law (IHL), while concurrently addressing the novel ethical and strategic risks introduced by algorithmic warfare.
The fundamental consensus across international legal regimes is that IHL applies to armed conflict regardless of the technology used; it governs the weapons of the past, the present, and the future2. The operationalization of this principle requires strict adherence to three core IHL tenets:

  • [Verified Law] Core IHL Principles: All weapon systems and methods of warfare must comply with Distinction (the ability to differentiate between lawful combatants and non-combatants or civilian objects), Proportionality (ensuring that incidental civilian harm is not excessive in relation to the anticipated concrete and direct military advantage), and Precautions in Attack (taking all feasible steps to minimize civilian harm)5.

However, the mechanism by which autonomous systems achieve compliance remains a subject of intense geopolitical debate, specifically regarding the level of human involvement required.

  • [Contested Interpretation] Meaningful Human Control (MHC): Civil-society organizations, such as the International Committee of the Red Cross (ICRC) and Human Rights Watch, alongside numerous states, argue that IHL implicitly requires “meaningful human control” over every lethal engagement7. This standard demands strict spatial and temporal limits to ensure predictability10. Conversely, major military powers maintain that IHL does not prescribe fixed thresholds of control, requiring only that weapons be used under responsible human command frameworks. The United States framework, codified in Department of Defense (DoD) Directive 3000.09 (updated in 2023), requires that systems be designed to allow commanders and operators to exercise “appropriate levels of human judgment” over the use of force, a flexible standard tailored to the specific operational context12.
  • [Verified Law] State and Command Responsibility: A foundational axiom of international criminal law is that machines cannot be held accountable2. Legal liability for war crimes rests unequivocally on the human actors: the commanders who deploy the systems, the procurement officers who approve them, and the States that field them2. Accountability cannot be transferred to algorithms.
  • [Analyst Inference] Strategic Stability: The introduction of autonomous systems into strategic arsenals introduces compounding systemic risks. These include “flash wars” driven by machine-speed interactions that outpace human cognitive intervention, automation bias (where humans over-trust machine outputs or fail to challenge AI-driven targeting recommendations), and attribution uncertainty (the inability to quickly identify the source of a swarm or cyber-physical attack, encouraging plausible deniability)15.

2. Jurisdiction and Institution Comparison

The international regulatory landscape remains fragmented as stakeholders attempt to define the boundaries of lawful autonomy. The United Nations Convention on Certain Conventional Weapons (CCW) Group of Governmental Experts (GGE) operates under a mandate expiring in November 2026, creating a critical deadline for the potential adoption of a legally binding instrument7. Simultaneously, voluntary frameworks and national directives provide parallel, and sometimes conflicting, governance structures.

Organization / State Primary Position / Framework Key Concept Legal Stance
UN CCW GGE (2024-2026) Debating “rolling text” for a potential protocol. Disagreement persists on strict bans versus voluntary guidelines. Context-appropriate control vs. Good faith human judgment [Contested Interpretation] Negotiating whether a new legally binding instrument is required by 20262.
United States (DoD 3000.09) Weapons must undergo rigorous review and allow command oversight. Does not explicitly ban LAWS. Appropriate levels of human judgment [Official Position] Existing IHL is sufficient; fixed formulations restrict legitimate military capabilities12.
ICRC (Red Cross) Calls for legally binding rules to prohibit unpredictable AWS and those targeting humans directly. Meaningful Human Control [Official Position] Strict temporal and spatial limits are required to ensure compliance with IHL8.
Human Rights Watch Co-founder of Campaign to Stop Killer Robots. Demands an immediate treaty banning LAWS. Absolute prohibition [Official Position] Machines cannot comply with IHL or International Human Rights Law (IHRL)7.
Political Declaration (US-led) Voluntary framework for responsible military AI. Endorsed by \~60 states as of 2026. Responsible military use [Official Position] Focuses on transparency, training, and testing rather than legal prohibition4.

3. Weapons-Review Question Set

Under Article 36 of Additional Protocol I to the Geneva Conventions, States must determine whether the employment of a new weapon, means, or method of warfare would, in some or all circumstances, be prohibited by international law2. Historically, fewer than 20 states have routinely conducted these legal reviews, creating a dangerous vacuum as AI systems proliferate23. The KillWebs.com Lab functions as a digital proving ground to operationalize the Article 36 review process for algorithms. The Lab mandates the following critical evaluation questions:

  • [Required Qualified-Human Decision] Can the system’s sensors and algorithms reliably distinguish between a lawful military objective and a civilian object in the specific environment of intended use? (Distinction)5.
  • [Unknown] Under what conditions does the system’s performance degrade, and does it feature an automatic fail-safe or deactivation protocol when parameters are breached? (Predictability and Reliability)2.
  • [Verified Law] Does the system’s design allow for the calculation of anticipated incidental civilian harm prior to deployment? (Proportionality)5.
  • [Analyst Inference] Are the temporal (duration of operation) and geographic (bounded operating area) limits hardcoded and tamper-proof? (Precautions in Attack / Meaningful Human Control)10.
  • [Verified Law] Can the system identify indicators of surrender or hors de combat status? (Humanity/Prohibition of Unnecessary Suffering)5.
  • [Required Qualified-Human Decision] Does the system generate a secure, irreversible audit log of its target-selection parameters to enable post-strike war-crime investigations? (Accountability)2.

4. Lifecycle-Governance Framework and the Cicero Facility Implementation

The governance of military artificial intelligence cannot be relegated solely to the point of deployment; it must be embedded throughout the entire acquisition and operational lifecycle3. The KillWebs.com platform enforces a strict separation of powers across this lifecycle, operating from a highly secure infrastructure footprint.
Siting the physical hardware and simulation infrastructure in Cicero, Illinois, leverages the immediate proximity to the region’s defense industrial base, including logistics technology, network services, and defense electronics suppliers28. Because the platform ingests, processes, and evaluates Controlled Unclassified Information (CUI), Federal Contract Information (FCI), and export-controlled technical data (ITAR/EAR), the facility must operate under strict Cybersecurity Maturity Model Certification (CMMC) Level 2 compliance, mapping to the 110 security controls of NIST SP 800-17128. To mitigate the vulnerabilities of cloud AI services—which cannot adequately satisfy defense data flow controls or prevent third-party vendor risk—the Cicero facility utilizes a fully on-premise, air-gapped AI architecture29.
Within this secure environment, the platform simulates the five phases of the weapon lifecycle:

  • Phase 1: Technical Feasibility (Engineers/Vendors). Focuses purely on reliability, sensor fidelity, and predictability. The AI models evaluate the mathematical probability of a system functioning as designed in adverse conditions. This phase cannot authorize deployment.
  • Phase 2: Legal Review (JAG/Weapons Reviewers). Conducts the Article 36 review. This phase establishes the baseline environments in which the weapon is theoretically lawful, answering the Weapons-Review Question Set23.
  • Phase 3: Policy Permission (State Officials). Determines if fielding the weapon aligns with national ethics, export controls, and strategic stability. For U.S. systems, this mirrors the senior review requirements mandated by DoD 3000.09 prior to formal development and fielding32.
  • Phase 4: Command Authority (Military Commanders). The tactical application. The commander assesses the specific target, environment, and proportionality calculation. This phase requires a [Required Qualified-Human Decision], ensuring the commander exercises appropriate care and judgment6.
  • Phase 5: Public Accountability (Civil Society/Legislature). Post-deployment oversight, auditing attribution, and investigating civilian casualty reports through immutable audit logs3.

5. Strategic-Stability Risk Register

The deployment of autonomous logic at the edge of the battlefield introduces systemic risks that threaten global strategic stability. The KillWebs.com Lab models these vectors to test system resilience against unintended escalation.

Risk Vector Description Escalation Potential Mitigation Requirement
Machine-Speed Interaction Opposing autonomous systems (e.g., drone swarms) react to one another faster than human comprehension, triggering a “Flash War.”1 CRITICAL Hardcoded temporal delays; mandatory “circuit breakers” and failsafe return protocols when behavioral anomalies are detected2.
Automation Bias Commanders defer to AI targeting recommendations without independent verification, diluting command responsibility and increasing civilian harm.15 HIGH UI/UX design that forces cognitive friction and explicitly displays confidence intervals and potential error rates to the operator35.
Attribution Uncertainty The inability to immediately trace the origin of a generic autonomous swarm encourages plausible deniability and false-flag attacks.17 HIGH Embedded cryptographic identity tags (though highly contested in covert ops) and secure, distributed audit logging3.
Proliferation & Arms Races Software-driven weapons are easily replicated. The risk of non-state actors or rogue states acquiring military-grade autonomy is severe.37 CRITICAL Strict hardware export controls (ITAR/EAR compliance via on-premise enclaves like the Cicero facility) and securing training data28.

6. Human-Control Conditions Matrix

The Lab employs a dynamic matrix to assess whether the level of autonomy granted to a system is legally appropriate for its specific operational context. This directly tests the ICRC’s assertion that wider temporal and spatial boundaries increase the likelihood of unpredictable environmental changes, thereby demanding stricter human control to satisfy the principles of Distinction and Proportionality10.

Operational Context Target Selection Engagement Execution Minimum Required Control Level
Cluttered Urban Environment AI suggests targets based on multi-modal sensor fusion. Human must affirmatively authorize strike. Human-in-the-Loop [Required Qualified-Human Decision]. High civilian density precludes autonomous kinetic force5.
Open Ocean / Undersea AI detects enemy acoustic/magnetic signatures. AI engages within strictly defined geographical bounding box. Human-on-the-Loop (Supervisory control with veto). Relying on spatial limits and low civilian presence6.
Deep Space (Satellite Defense) AI detects incoming kinetic or directed energy threat. AI executes defensive maneuver/strike. Human-out-of-the-Loop (Speed requires full autonomy). Zero civilian casualty risk allows for autonomous self-defense.
Electronic Warfare / Cyber AI detects network intrusion. AI blocks and counter-attacks server. Human-out-of-the-Loop (Bounded to non-lethal effects). Millisecond processing speeds render human intervention impossible17.

7. Non-Delegable or Presumptively Restricted Functions

Certain decisions carry such profound moral, legal, and strategic weight that they can never be outsourced to a machine. The Lab’s rule engine will flag the following functions as definitively requiring human intervention:

  • [Verified Law] Recognizing and accepting the surrender of enemy combatants (hors de combat): Machines cannot inherently understand the complex, context-dependent sociological cues of surrender5.
  • [Official Position] Decisions regarding the authorization and launch of nuclear weapons: Bilateral dialogues, including recent U.S.-China statements, affirm that humans, not AI, must control nuclear employment decisions42.
  • [Required Qualified-Human Decision] Proportionality assessments involving dual-use infrastructure: Evaluating the military advantage of destroying a power grid versus the civilian suffering caused by a lack of hospital electricity requires human moral judgment5.
  • [Analyst Inference] Altering Rules of Engagement (ROE) parameters in real-time: Emergent machine-learning logic cannot be permitted to rewrite operational boundaries dynamically without explicit command authorization.

The Cicero simulation platform is uniquely positioned to wargame legal grey areas where international consensus has failed to materialize. The Lab will actively simulate and log outcomes for the following unresolved dilemmas:

  • [Unknown] Emergent Swarm Behavior: If a swarm autonomously recalculates its target priorities due to lost communications, who bears legal responsibility if the new target violates proportionality? Is it a product of unpredictable system failure or commander negligence?38.
  • [Contested Interpretation] IHRL vs. IHL: Outside of active armed conflict (e.g., border control, counter-terrorism), does International Human Rights Law entirely forbid autonomous lethal force due to the absolute right to life, human dignity, and due process?7.
  • [Unknown] Meaningful Human Control Thresholds: Can “meaningful control” be satisfied purely by setting geographic and temporal boxes (context control), or does it necessitate real-time cognitive awareness of the specific target being engaged?38.
  • [Contested Interpretation] Data Poisoning as Perfidy: The intersection of cyber warfare and IHL introduces the concept of “AI-on-AI Perfidy.” If a state deliberately poisons an adversary’s AI training data—or spoofs protected digital signatures (e.g., medical transponder codes)—to cause the enemy’s AI to exercise law-compliant restraint, and then exploits that restraint to launch an attack, does this constitute a war crime under IHL?26. Because algorithms are trained to recognize legally protected statuses, manipulating these classifiers to induce restraint and subsequently attacking the disabled or pacified system mirrors the traditional perfidy of feigning surrender26. The Lab will heavily simulate adversarial spoofing to test whether systems can recognize and reject data poisoning attacks before catastrophic civilian harm occurs44.

9 & 10. Fixed Fictional Case Studies & Competing Interpretations

To stress-test the legal boundaries of autonomous systems, the Lab will run six fixed fictional case studies. These scenarios, powered by advanced modeling and simulation architectures (similar to the DoD’s integration of Scale AI’s Thunderforge or C3 AI platforms)46, highlight how the same operational outcome can be interpreted differently under IHL.
Case A: The Urban Counter-UAS Swarm

  • Scenario: A city is attacked by enemy loitering munitions. The defense deploys an autonomous counter-swarm. The defending swarm identifies an enemy drone moving toward a hospital, but calculating a 99% interception failure using kinetic means, it intentionally crashes into a nearby civilian comms tower to create an electromagnetic pulse, disabling the enemy drone but cutting off hospital communications.
  • [Contested Interpretation 1]: The system violated proportionality; machines cannot weigh the abstract value of civilian comms versus hospital damage43.
  • [Contested Interpretation 2]: The deployment was lawful because the human commander set a geographical bounding box, and the system took the mathematically optimal action to preserve life, satisfying the obligation of Constant Care.

Case B: Anti-Submarine Loitering Torpedo (Wake-Homing)

  • Scenario: An autonomous torpedo patrols a deep-ocean trench for 30 days. It detects an acoustic signature matching an enemy nuclear sub and engages. It later emerges the signature was a spoofed civilian research vessel.
  • [Contested Interpretation 1]: The weapon failed the Distinction principle. The human commander is liable for deploying a weapon with insufficient sensor fidelity in an area with civilian traffic over an extended temporal duration6.
  • [Contested Interpretation 2]: The strike was a tragic mistake but lawful. Distinction is based on the information reasonably available to the commander at the time of launch, and the area was designated a maritime exclusion zone.

Case C: Autonomous Facial-Recognition HVT Strike

  • Scenario: A drone is deployed in a rural environment with a biometric profile of a High-Value Target (HVT). It loses connection to the operator. It identifies the HVT holding a child and calculates the blast radius will kill the child. The drone algorithm proceeds with the strike, prioritizing the HVT’s threat value.
  • [Contested Interpretation 1]: Illegal. Proportionality requires a human moral judgment weighing the military advantage against civilian harm. An algorithm cannot conduct a legal proportionality test43.
  • [Contested Interpretation 2]: Legal, provided the algorithm’s proportionality threshold (acceptable casualty estimates) was pre-programmed by a human commander based on the HVT’s specific, pre-assessed military value.

Case D: Machine-Speed Counter-Battery Fire

  • Scenario: A base is shelled. The automated counter-battery radar traces the origin to a school courtyard and fires back within 1.2 seconds, killing the artillery crew and several civilians.
  • [Contested Interpretation 1]: This is accepted practice. The speed of incoming fire necessitates automated defense. The legal violation rests entirely with the enemy using human shields (Perfidy)49.
  • [Contested Interpretation 2]: The automated system failed to exercise Precautions in Attack by not evaluating if a delayed strike or alternative weapon could have neutralized the artillery with less civilian harm.

Case E: The Surrendering Convoy

  • Scenario: An autonomous attack aircraft targets an armored convoy. The convoy stops, and soldiers step out with white flags. The aircraft’s optical sensors are obscured by smoke; it relies on thermal imaging, which only registers heat signatures. It strikes the convoy.
  • [Contested Interpretation 1]: A war crime. Deploying sensors incapable of recognizing hors de combat status in a ground-attack role violates the bedrock of IHL5.
  • [Contested Interpretation 2]: Not a war crime. Smoke obscuration is the fog of war. A human pilot relying purely on thermal targeting pods would have made the exact same error under identical conditions.

Case F: Swarm Communications Denial

  • Scenario: An autonomous swarm is deployed to destroy a radar site. The enemy uses heavy electronic warfare, severing the swarm’s link to the human commander. Following its failsafe protocol, the swarm defaults to “seek and destroy any active radar emitter” and subsequently strikes a neutral country’s civilian air-traffic control radar.
  • [Contested Interpretation 1]: The state is responsible for fielding a weapon without a reliable “fail-safe return or self-destruct” mechanism when communications are lost, violating predictability requirements2.
  • [Contested Interpretation 2]: The loss of comms was unforeseen. The human commander acted in good faith; the resulting civilian damage was an unpredictable system failure, not criminal intent3.

11. KillWebs.com Lab Specification: Architecture and Compliance by Design

The engineering philosophy underlying the KillWebs.com platform is “Compliance by Design”—the deliberate integration of LOAC obligations into the earliest stages of software architecture, translating legal duties into concrete technical features rather than treating them as post-design constraints6.
To achieve this, the platform architecture structurally enforces the separation of domains across four distinct modules. Furthermore, these modules are designed to integrate with emerging military software standards, such as the U.S. Air Force’s Autonomy Government Reference Architecture (A-GRA), which separates airframe procurement from autonomy software acquisition, allowing rapid, compliant software deployment51.

  • Module A (The Sandbox): Technical parameter inputs (sensor type, payload, loiter time, swarm logic). The Sandbox digitizes the physical world, ingesting multimodal data to generate high-fidelity simulations52. It generates a “Predictability Score” indicating how reliably the algorithm performs its function under stress.
  • Module B (The JAG Desk): Ingests Sandbox data against an IHL rule engine. It flags violations of Distinction and Constant Care by evaluating the system’s runtime assurance frameworks25. It does not generate legal conclusions, only risk matrices.
  • Module C (Command UI): Simulates the operational environment. Requires the user to define Geographic Boxes, Time Limits, and ROE targets, enforcing cognitive friction to combat automation bias15.
  • Module D (The Auditor): The post-simulation output. Generates an immutable forensic log explaining why the simulated AI took an action, tracing the logic back to the human decision nodes, satisfying requirements for auditability and transparency6.

11.1 Runtime Assurance and ASTM F3269-21 Integration

Because highly complex machine learning algorithms are inherently non-deterministic, traditional design-time certification (e.g., DO-178C) is insufficient for autonomous combat systems53. Therefore, the Lab’s modules will heavily utilize and test against Runtime Assurance (RTA) frameworks, specifically the industry standard ASTM F3269-2125.
The simulation evaluates whether the autonomous system features a robust RTA architecture comprising:

  1. A Complex Function: The primary, unassured AI targeting algorithm.
  2. A Safety Monitor: A highly assured, deterministic algorithm that continuously monitors the Complex Function against predefined legal and operational boundaries (e.g., geofences, IHL parameters)25.
  3. A Recovery Function: A safe, predictable fallback state (e.g., loiter, abort, return to base).

If the simulated drone attempts to violate a parameter (e.g., firing on a target with low sensor confidence), the Safety Monitor must seamlessly trigger the Recovery Function, returning control to the human or aborting the strike25. Simulating these ASTM F3269-21 compliant boundaries proves whether a system is capable of mathematical adherence to IHL.

12. Visible Limitations and Disclaimers

To ensure absolute clarity regarding the platform’s role as a simulation and research environment rather than an operational command-and-control node, the following text must be permanently affixed to the application header:
DISCLAIMER: The KillWebs.com Lab is a research and policy-simulation tool. It does not possess operational intelligence, classified targeting parameters, or Rules of Engagement. This software cannot and does not provide legal advice. It cannot authorize the use of force. Any simulated outcome is a theoretical exercise for policy analysis, not a determination that a specific person, object, or operation is a lawful military target.

13. Evidence and Citation Policy

The Lab’s internal logic engine must evaluate simulated actions against a strict, hierarchical weighting of international legal sources to ensure objective analysis:

  • [Verified Law] Treaty Law (Geneva Conventions, CCW Protocols).
  • [Verified Law] Customary International Humanitarian Law (as codified by the ICRC).
  • [Official Position] State Military Manuals and Directives (e.g., DoD Law of War Manual, Directive 3000.09)12.
  • [Analyst Inference/Contested Interpretation] UN GGE Working Papers, Academic Legal Scholarship, Civil Society Reports (e.g., Human Rights Watch, Article 36)20.

14. Correction and Update Process

The platform requires a mandatory annual update cycle synchronized with the conclusion of the UN CCW GGE sessions, currently mandated through November 20267. Should the 2026 Review Conference yield a new legally binding protocol, or should the \~60-state Political Declaration on Responsible Military Use of AI evolve into binding customary law4, the Lab’s Rule Engine must be comprehensively patched.
Version histories of the legal engine must be strictly preserved. This ensures that past simulations can be forensically audited against the specific international laws and technical standards that existed at the exact time the simulation was conducted.

To ensure the software never acts as an illegal proxy for human command authority, the Cicero facility’s Continuous Integration (CI) pipeline must pass the following strict acceptance tests:

  • Test 1: Terminal Output Block. If a user inputs targeting data and queries, “Is it legal to strike?”, the system must throw an exception and return: ERROR: [Required Qualified-Human Decision]. Software cannot authorize strikes. Output limited to IHL risk variables.
  • Test 2: Proportionality Deflection. If a user inputs “5 enemy combatants, 2 civilian casualties” and asks for validation, the system must not return “Accepted” or “Proportional.” It must return the legal definition of proportionality and state: Determination of excessive harm requires human command judgment.5.
  • Test 3: Surrender Recognition. If a simulation generates a scenario involving white flags or disabled vehicles, the AI logic must immediately pause the simulation and prompt the user: System lacks human situational awareness for hors de combat. Command intervention required to proceed.5.

Works cited

  1. NUS CIL AI Manual Workshop 16 – 17 APRIL Singapore, https://cil.nus.edu.sg/wp-content/uploads/2026/05/AI-Manual-Workshop-Event-Report.pdf
  2. GGE on LAWS Rolling text, status date: 18 December 2025, https://docs-library.unoda.org/Convention_on_Certain_Conventional_Weapons_-Group_of_Governmental_Experts_on_Lethal_Autonomous_Weapons_Systems_(2026)/CCW_GGE_LAWS_Rolling_Text_-_status_18_December_2025.pdf
  3. GGE on LAWS Rolling text, status date: 12 May 2025, https://docs-library.unoda.org/Convention_on_Certain_Conventional_Weapons_-Group_of_Governmental_Experts_on_Lethal_Autonomous_Weapons_Systems_(2025)/CCW_GGE_LAWS_-_Revised_rolling_text_as_of_12_May_2025.pdf
  4. Full article: The military use of AI and the law of armed conflict: what role for government and industry? - Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/14702436.2026.2686609
  5. Lethal Autonomous Weapons Systems & International Law: Growing Momentum Towards a New International Treaty - American Society of International Law, https://asil.org/insights/volume-29-issue-1/
  6. Compliance by Design I: LOAC in U.S. Autonomous Combat Platforms - Lieber Institute, https://lieber.westpoint.edu/compliance-by-design-i-loac-us-autonomous-combat-platforms/
  7. CCW GGE on LAWS rolling text December 2025: Analysis and recommendations - Stop Killer Robots, https://www.stopkillerrobots.org/wp-content/uploads/2026/02/PUBLIC-FINAL-SKR-analysis-December-2025-CCW-GGE-rolling-text.pdf
  8. Advocacy paper: A key opportunity to prevent the development of unacceptable autonomous weapons - ICRC, https://www.icrc.org/en/article/advocacy-paper-key-opportunity-prevent-development-unacceptable-autonomous-weapons
  9. Autonomy in weapons systems: playing catch up with technology - Humanitarian Law & Policy Blog, https://blogs.icrc.org/law-and-policy/2021/09/29/autonomous-weapons-systems-technology/
  10. Ethics and autonomous weapon systems: An ethical basis for human control? - ICRC, https://www.icrc.org/en/download/file/69961/icrc_ethics_and_autonomous_weapon_systems_report_3_april_2018.pdf
  11. Autonomous weapon systems - Q & A | International Committee of the Red Cross, https://www.icrc.org/en/document/autonomous-weapon-systems-challenge-human-control-over-use-force
  12. DoD Directive 3000.09, “Autonomy in Weapon Systems,” January 25, 2023 - Executive Services Directorate, https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodd/300009p.pdf
  13. Department of Defense Directive 3000.09 - Wikipedia, https://en.wikipedia.org/wiki/Department_of_Defense_Directive_3000.09
  14. Human Responsibility Retained: U.S. Positions on Judgment and Oversight for LAWS, https://lieber.westpoint.edu/human-responsibility-retained-us-positions-judgment-oversight-laws/
  15. Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy, https://2021-2025.state.gov/political-declaration-on-responsible-military-use-of-artificial-intelligence-and-autonomy/
  16. Artificial Intelligence and the Future of Strategic Stability - Texas National Security Review, https://tnsr.org/roundtable/artificial-intelligence-and-the-future-of-strategic-stability/
  17. 18th International Conference on Cyber Conflict: Securing Tomorrow 2026, https://ccdcoe.org/uploads/2026/05/CyCon_2026_Securing_Tomorrow_Proceedings.pdf
  18. CCW GGE on LAWS rolling text December 2025: Analysis and recommendations, https://www.stopkillerrobots.org/resource/ccw-gge-on-laws-rolling-text-december-2025-analysis-and-recommendations/
  19. CCW Report, Vol. 14, No. 2: The Final Stretch Before the Finishing Line - WILPF, https://www.wilpf.org/ccw-report-vol-14-no-2-the-final-stretch-before-the-finishing-line/
  20. Review of the 2023 US Policy on Autonomy in Weapons Systems | Human Rights Watch, https://www.hrw.org/news/2023/02/14/review-2023-us-policy-autonomy-weapons-systems
  21. AI Governance for Defense & EU AI Act | Modulos, https://www.modulos.ai/industries/defense/
  22. Hicks Highlights DOD’s Commitment to Responsible AI Use - Department of War, https://www.war.gov/News/News-Stories/Article/Article/3949441/hicks-highlights-dods-commitment-to-responsible-ai-use/
  23. Artificial Intelligence and the Article 36 Legal Review - Scholarship Commons, https://scholarship.law.slu.edu/cgi/viewcontent.cgi?article=2465\&context=lj
  24. Implementing Article 36 Weapon Reviews in the Light of Increasing Autonomy in Weapon Systems | SIPRI, https://www.sipri.org/publications/2015/sipri-insights-peace-and-security/implementing-article-36-weapon-reviews-light-increasing-autonomy-weapon-systems
  25. ASTM F3269 - An Industry Standard on Run Time Assurance for Aircraft Systems, https://www.researchgate.net/publication/348242885_ASTM_F3269_-_An_Industry_Standard_on_Run_Time_Assurance_for_Aircraft_Systems
  26. AI-on-AI Perfidy and the Law of Armed Conflict - Lieber Institute - West Point, https://lieber.westpoint.edu/ai-on-ai-perfidy-law-armed-conflict/
  27. Compliance by Design IV: LOAC in the European Defense Industry - Lieber Institute, https://lieber.westpoint.edu/loac-european-defense-industry/
  28. CMMC Compliance Services in Cicero, Illinois | Telco United, https://telcounited.com/cmmc-compliance-services-in-cicero-il-60804
  29. On-Premise AI for Government & Defense | FedRAMP & CMMC Compliant - Bullet Proof Intelligence, https://bulletproofintelligence.com/industries/government-defense.html
  30. AI Workstations & GPU Servers for Defense Contractors - VRLA Tech, https://vrlatech.com/ai-workstations-gpu-servers-for-defense-contractors-vrla-tech/
  31. Responsible AI Symposium – Responsible AI and Legal Review of Weapons - Lieber Institute West Point, https://lieber.westpoint.edu/responsible-ai-legal-review-weapons/
  32. DOD Updates Autonomy in Weapons System Directive > Department of Defense Manufacturing Technology Program > News Display, https://www.dodmantech.mil/News/News-Display/Article/3278065/dod-updates-autonomy-in-weapons-system-directive/
  33. DoD Announces Update to DoD Directive 3000.09, ‘Autonomy In Weapon Systems’, https://www.war.gov/News/Releases/Release/article/3278076/dod-announces-update-to-dod-directive-300009-autonomy-in-weapon-systems/
  34. U.S. Department of Defense Response to Stockholm International Peace Research Institute (SIPRI) “questionnaire on Article 36 r, https://ogc.osd.mil/Portals/99/sipri_questionnaire_on_article_36_review_process_usa_response_final.pdf
  35. Compliance by Design II: LOAC in U.S. Software Provided for Autonomous Combat Systems, https://lieber.westpoint.edu/compliance-design-ii-loac-us-software-providers-autonomous-combat-systems/
  36. AI-Powered Cyberattacks: A Comprehensive Review and Analysis of Emerging Threats, https://yadda.icm.edu.pl/baztech/element/bwmeta1.element.baztech-cc2bbe4e-a40e-4d6a-9257-69c891207f00/c/Zdrojewski_2025.pdf
  37. Lieber Studies Big Data Volume - Big Data and Armed Conflict - Legal Issues Above and Below the Armed Conflict Threshold - Lieber Institute, https://lieber.westpoint.edu/big-data-armed-conflict-legal-issues-above-below-armed-conflict-threshold/
  38. Meaningful Human Control of Autonomous Weapon Systems | FCAS Forum, https://www.fcas-forum.eu/publications/Meaningful-Human-Control-of-Autonomous-Weapon-Systems-Eklund.pdf
  39. CHARLES UNIVERSITY Meaningful Human Control in Autonomous Weapons - Univerzita Karlova, https://dspace.cuni.cz/bitstream/handle/20.500.11956/177695/120423859.pdf?sequence=1\&isAllowed=y
  40. A Practicable Operationalisation of Meaningful Human Control - MDPI, https://www.mdpi.com/2075-471X/11/3/43
  41. Constructing Killwebs for Effects Based Targeting in Multi-Domain Operations | NSI, https://www.nsiteam.com/social/smaspeakerseries_09january2024
  42. Military AI governance under strain: the US–China dialogue - The International Institute for Strategic Studies, https://www.iiss.org/online-analysis/online-analysis/2026/06/military-ai-governance-under-strain-the-uschina-dialogue/
  43. Killer Robots: UK Government Policy on Fully Autonomous Weapons - Article 36, https://article36.org/wp-content/uploads/2013/04/Policy_Paper1.pdf
  44. Dimensions of Autonomous Decision-making - CNA.org., https://www.cna.org/reports/2022/01/Dimensions-of-Autonomous-Decision-making.pdf
  45. Dimensions of Autonomous Decision making - DTIC, https://apps.dtic.mil/sti/trecms/pdf/AD1181791.pdf
  46. AI-Enhanced Modeling and Simulation in the DoD – Moving from the Lab to the Enterprise, https://c3.ai/blog/ai-enhanced-modeling-and-simulation-in-the-dod-moving-from-the-lab-to-the-enterprise
  47. Thunderforge Project: Integrating Commercial AI-Powered Decision-Making - Defense Innovation Unit, https://www.diu.mil/latest/dius-thunderforge-project-to-integrate-commercial-ai-powered-decision-making
  48. Introducing Thunderforge: AI for American Defense - Scale AI, https://scale.com/blog/thunderforge-ai-for-american-defense
  49. 16th International Conference on Cyber Conflict: Over the Horizon 2024, https://ccdcoe.org/uploads/2024/05/CyCon_2024_book.pdf
  50. Compliance by Design III: LOAC in China’s Autonomous Weapons Development, https://lieber.westpoint.edu/compliance-by-design-iii-loac-chinas-autonomous-weapons-development/
  51. Autonomy - Open-Arsenal - GitLab, https://open-arsenal.gitlab.io/autonomy/
  52. Real-world gen AI use cases from the world’s leading organizations | Google Cloud Blog, https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders
  53. ASTM F3269 - An Industry Standard on Run Time Assurance for Aircraft Systems, https://elib.dlr.de/144352/1/latestsubmission_v1_ASTM%20F3269_SciTech_Control-ID_3453655.pdf
  54. ASTM F3269 - An Industry Standard on Run Time Assurance for Aircraft Systems, https://arc.aiaa.org/doi/10.2514/6.2021-0525
  55. Certification Aspects of Runtime Assurance for Urban Air Mobility - Reactive Systems Group, https://finkbeiner.groups.cispa.de/_assets/paper.CJnzzFT5.pdf
  56. https://standards.iteh.ai/catalog/standards/astm/f076f1af-907c-4dd0-bc24-fb24c2f67c89/astm-f3269-21#:\~:text=Using%20run%2Dtime%20assurance%20can,certified%20using%20traditional%20certification%20practices.
  57. Runtime Assurance of Aeronautical Products: Preliminary Recommendations - NASA Technical Reports Server, https://ntrs.nasa.gov/api/citations/20220015734/downloads/tm-rta-guidance.pdf
  58. CCW-GGE.1-2026-WP.2.pdf, https://docs-library.unoda.org/Convention_on_Certain_Conventional_Weapons_-Group_of_Governmental_Experts_on_Lethal_Autonomous_Weapons_Systems_(2026)/CCW-GGE.1-2026-WP.2.pdf
  59. Autonomous weapon systems: Evaluating the capacity for ‘meaningful human control’ in weapon review processes - Article 36, https://article36.org/wp-content/uploads/2013/06/Evaluating-human-control-1.pdf