New Research Paper: Autonomous Cyber Capabilities under International Law

The application of international law to cyber operations and to the use of autonomous military technology continues to be the subject of intensive debate. Nevertheless, the legal implications of autonomous cyber capabilities have thus far received little attention. A new research paper on autonomous cyber capabilities under international law was published jointly by Dr Rain Liivoja from the University of Queensland together with the NATO CCDCOE researchers Maarja Naagel and Ann Väljataga.

The interconnection between autonomy and cyber together with the international law aspects of autonomous cyber capabilities have not yet been thoroughly explored. While there are still debatable legal issues related to regular cyber capabilities, there is a multitude of wholly unresolved issues concerning the regulations applying to autonomous weapon systems. As a result, the ambition of this paper is not to come up with definitive answers or draw a comprehensive list of related legal and policy issues.

Instead, the paper first provides a general technological background to explain how the autonomous technological systems work and also gives examples of autonomous functionality in defensive and offensive cyber capabilities. Next, the paper makes a few overarching observations about the relationship between autonomy and the law, and then describes possible breaches of sovereignty that may result from the use of autonomous functionality in cyber capabilities. The paper then looks at autonomous cyber capabilities in the context of ius ad bellum and ius in bello respectively, and in the end, explores the responsibility under international law for uses of autonomous cyber capabilities.

‘Autonomous Cyber Capabilities under International Law’ paper is available online at CCDCOE’s website. This research paper is an independent product of the CCDCOE and does not represent the official policy or position of NATO or any of the CCDCOE´s Sponsoring Nations.

The NATO Cooperative Cyber Defence Centre of Excellence (NATO CCDCOE) is a NATO-accredited knowledge hub, research institution, and training and exercise facility. The Tallinn-based international military organisation focuses on interdisciplinary applied research, as well as consultations, trainings and exercises in the field of cyber security.