This post catalogs the bases for attribution of non-State actor conduct and asks how the fact that conduct involves AI affects attribution. It concludes that while AI doesn't create new legal gaps in State responsibility, it complicates establishing factual links and determining the scope of control, potentially leading to challenges in accountability.
Introduction: AI, Non-State Actors, and State Responsibility This article, part of the Lieber Studies series, examines the attribution of artificial intelligence (AI)-related conduct by non-State actors during armed conflict to States. The authors, Michael N. Schmitt and Klaudia Klonowska, highlight the increasing involvement of private entities in AI development and operation for military applications. They investigate whether AI exacerbates the ambiguity in attributing actions between States and non-State actors. The central argument is that the existing legal framework for State responsibility is largely adequate for AI-related conduct, even unexpected AI behaviors, but practical challenges in establishing accountability may arise due to 'fault' requirements in primary rules and the difficulty of tracing AI-enabled actions. The Basics of State Responsibility The article establishes the foundation of State responsibility, drawing on customary international law and the International Law Commission's (ILC) Articles on the Responsibility of States for Internationally Wrongful Acts (ARSIWA). An 'internationally wrongful act' requires both a breach of an international law obligation and attribution of that breach to a State. Crucially, AI systems themselves are not subjects of international law, nor are they considered non-State actors for attribution purposes. All attribution questions regarding AI ultimately focus on the human and institutional conduct associated with the AI system's lifecycle, from development to deployment. Attribution does not inherently require causation or fault, meaning unintended AI conduct can still be attributed to a State, though fault may be relevant to determining if a primary rule was breached. Bases for Attribution of AI-related Non-State Actor’s Conduct This section delves into various legal bases for attributing non-State actors' AI-related conduct to a State, ranking them by perceived likelihood of application. It explores how AI nuances interact with established rules of international law. Instructions or Direction or Control (ARSIWA Article 8) This is deemed the most probable rule for attributing non-State actor AI-related conduct. It applies if a non-State actor acts on specific instructions or under the 'effective control' of a State. 'Effective control' implies the State directed or controlled the specific operation, and the wrongful conduct was an integral part of it. AI systems can enhance a State's control (e.g., through remote parameter setting or override functions). However, attribution under this rule does not extend to `ultra vires` actions (actions exceeding authority or contravening instructions), referring to human conduct. Determining if a deviation (like adjusting an AI system's confidence threshold) is merely 'incidental' or a significant `ultra vires` act requires a contextual assessment, as even small AI changes can have substantial effects. Entities Exercising Elements of Government Authority (ARSIWA Article 5) Attribution under Article 5 occurs if non-State actors 'exercise elements of government authority.' This requires three conditions: the conduct is governmental authority (e.g., conduct of hostilities), the actor is empowered by the State's internal law (often through procurement), and the actor is acting in that capacity. AI-related activities like targeting or cyber operations qualify as governmental authority, but pre-deployment commercial activities (training models) might not. Unlike Article 8, `ultra vires` actions are attributable if the actor was performing legally authorized governmental functions. An example includes a private firm's AI agent unexpectedly counterattacking a neutral State, making the violations attributable to the contracting State. Conduct of De Facto State Organs (ARSIWA Article 4) This rule attributes conduct if a non-State actor functions as a 'de facto' organ of the State, meaning it acts in 'complete dependence' on the State. This can apply to technical organizations created outside formal governmental structures but wholly funded, equipped, and directed by the State, lacking operational autonomy. State ownership or funding alone is insufficient to establish 'complete dependence.' The AI-enabled nature of the conduct does not alter the factual assessment of dependence required for attribution. Similar to Article 5, `ultra vires` conduct by de facto organs is also attributable to the State. Acting in the Absence or Default of Official Authorities (ARSIWA Article 9) Under Article 9, conduct by a person or group exercising governmental authority is attributable to a State if official authorities are absent or failing in their duties, and the non-State actor's action is clearly necessary. This might be more relevant in AI contexts due to the specialized technical support military operations often require from commercial firms. An example is private engineers taking control of a complex AI-enabled weapons system in combat due to the absence of trained military operators. Attribution rests on the human decision to act in a governmental capacity during a vacuum of authority, irrespective of the AI's role in the ensuing conduct. Conduct Acknowledged and Adopted by a State as its Own (ARSIWA Article 11) Article 11 dictates that conduct not initially attributable to a State becomes so if the State acknowledges and adopts it as its own. This goes beyond mere approval, requiring the State to treat the conduct as if it were its own act, as exemplified by the `Tehran Hostages` judgment. The AI-related nature of the non-State actor's original conduct does not significantly impact this attribution rule; if adopted, the State assumes responsibility for the AI-enabled actions on the same basis as conventional ones. Conduct of an Insurrectional or Other Movement (ARSIWA Article 10) Article 10 attributes the conduct of an insurrectional movement to a State if that movement successfully becomes the new government or forms a new State. This rule holds limited direct significance for AI-related attribution, as the primary concern is the change in governmental status, not the technology used by the movement. Whether AI was involved would primarily affect the assessment of whether a primary rule of international law was breached. Establishing Attribution: Evidentiary and Investigative Challenges While the legal framework for attribution is generally sound, AI introduces significant evidentiary and investigative challenges. Identifying the source, operator, or responsible human actors behind AI-enabled actions can be complex, especially with AI designed for obfuscation or autonomous operation. An example of an AI agent spoofing identities in cyberspace highlights this. However, forensic analysis, as demonstrated by Ukrainian investigators recovering data from a Russian drone with an Nvidia computer module, suggests that AI-enabled conduct is not inherently untraceable. The ability to establish attribution depends heavily on the specific circumstances and available evidence. Concluding Thoughts The authors conclude that AI typically does not create new legal gaps in the law of State responsibility concerning attribution. Instead, its primary impact is on complicating the factual assessment of relationships between non-State actors, their conduct, and the State. This is particularly true when determining the scope of State instructions, the extent of effective control, and whether deviations from these parameters by AI systems were merely 'incidental' or amounted to `ultra vires` acts. The increasing complexity and reduced visibility of these relationships in AI-driven warfare pose a crucial challenge to international law: ensuring that AI does not inadvertently create pathways to practical impunity for States.
Introduction: AI, Non-State Actors, and State Responsibility
This article, part of the Lieber Studies series, examines the attribution of artificial intelligence (AI)-related conduct by non-State actors during armed conflict to States. The authors, Michael N. Schmitt and Klaudia Klonowska, highlight the increasing involvement of private entities in AI development and operation for military applications. They investigate whether AI exacerbates the ambiguity in attributing actions between States and non-State actors. The central argument is that the existing legal framework for State responsibility is largely adequate for AI-related conduct, even unexpected AI behaviors, but practical challenges in establishing accountability may arise due to 'fault' requirements in primary rules and the difficulty of tracing AI-enabled actions.
The Basics of State Responsibility
The article establishes the foundation of State responsibility, drawing on customary international law and the International Law Commission's (ILC) Articles on the Responsibility of States for Internationally Wrongful Acts (ARSIWA). An 'internationally wrongful act' requires both a breach of an international law obligation and attribution of that breach to a State. Crucially, AI systems themselves are not subjects of international law, nor are they considered non-State actors for attribution purposes. All attribution questions regarding AI ultimately focus on the human and institutional conduct associated with the AI system's lifecycle, from development to deployment. Attribution does not inherently require causation or fault, meaning unintended AI conduct can still be attributed to a State, though fault may be relevant to determining if a primary rule was breached.
Bases for Attribution of AI-related Non-State Actor’s Conduct
This section delves into various legal bases for attributing non-State actors' AI-related conduct to a State, ranking them by perceived likelihood of application. It explores how AI nuances interact with established rules of international law.
Instructions or Direction or Control (ARSIWA Article 8)
This is deemed the most probable rule for attributing non-State actor AI-related conduct. It applies if a non-State actor acts on specific instructions or under the 'effective control' of a State. 'Effective control' implies the State directed or controlled the specific operation, and the wrongful conduct was an integral part of it. AI systems can enhance a State's control (e.g., through remote parameter setting or override functions). However, attribution under this rule does not extend to `ultra vires` actions (actions exceeding authority or contravening instructions), referring to human conduct. Determining if a deviation (like adjusting an AI system's confidence threshold) is merely 'incidental' or a significant `ultra vires` act requires a contextual assessment, as even small AI changes can have substantial effects.
Entities Exercising Elements of Government Authority (ARSIWA Article 5)
Attribution under Article 5 occurs if non-State actors 'exercise elements of government authority.' This requires three conditions: the conduct is governmental authority (e.g., conduct of hostilities), the actor is empowered by the State's internal law (often through procurement), and the actor is acting in that capacity. AI-related activities like targeting or cyber operations qualify as governmental authority, but pre-deployment commercial activities (training models) might not. Unlike Article 8, `ultra vires` actions are attributable if the actor was performing legally authorized governmental functions. An example includes a private firm's AI agent unexpectedly counterattacking a neutral State, making the violations attributable to the contracting State.
Conduct of De Facto State Organs (ARSIWA Article 4)
This rule attributes conduct if a non-State actor functions as a 'de facto' organ of the State, meaning it acts in 'complete dependence' on the State. This can apply to technical organizations created outside formal governmental structures but wholly funded, equipped, and directed by the State, lacking operational autonomy. State ownership or funding alone is insufficient to establish 'complete dependence.' The AI-enabled nature of the conduct does not alter the factual assessment of dependence required for attribution. Similar to Article 5, `ultra vires` conduct by de facto organs is also attributable to the State.
Acting in the Absence or Default of Official Authorities (ARSIWA Article 9)
Under Article 9, conduct by a person or group exercising governmental authority is attributable to a State if official authorities are absent or failing in their duties, and the non-State actor's action is clearly necessary. This might be more relevant in AI contexts due to the specialized technical support military operations often require from commercial firms. An example is private engineers taking control of a complex AI-enabled weapons system in combat due to the absence of trained military operators. Attribution rests on the human decision to act in a governmental capacity during a vacuum of authority, irrespective of the AI's role in the ensuing conduct.
Conduct Acknowledged and Adopted by a State as its Own (ARSIWA Article 11)
Article 11 dictates that conduct not initially attributable to a State becomes so if the State acknowledges and adopts it as its own. This goes beyond mere approval, requiring the State to treat the conduct as if it were its own act, as exemplified by the `Tehran Hostages` judgment. The AI-related nature of the non-State actor's original conduct does not significantly impact this attribution rule; if adopted, the State assumes responsibility for the AI-enabled actions on the same basis as conventional ones.
Conduct of an Insurrectional or Other Movement (ARSIWA Article 10)
Article 10 attributes the conduct of an insurrectional movement to a State if that movement successfully becomes the new government or forms a new State. This rule holds limited direct significance for AI-related attribution, as the primary concern is the change in governmental status, not the technology used by the movement. Whether AI was involved would primarily affect the assessment of whether a primary rule of international law was breached.
Establishing Attribution: Evidentiary and Investigative Challenges
While the legal framework for attribution is generally sound, AI introduces significant evidentiary and investigative challenges. Identifying the source, operator, or responsible human actors behind AI-enabled actions can be complex, especially with AI designed for obfuscation or autonomous operation. An example of an AI agent spoofing identities in cyberspace highlights this. However, forensic analysis, as demonstrated by Ukrainian investigators recovering data from a Russian drone with an Nvidia computer module, suggests that AI-enabled conduct is not inherently untraceable. The ability to establish attribution depends heavily on the specific circumstances and available evidence.
Concluding Thoughts
The authors conclude that AI typically does not create new legal gaps in the law of State responsibility concerning attribution. Instead, its primary impact is on complicating the factual assessment of relationships between non-State actors, their conduct, and the State. This is particularly true when determining the scope of State instructions, the extent of effective control, and whether deviations from these parameters by AI systems were merely 'incidental' or amounted to `ultra vires` acts. The increasing complexity and reduced visibility of these relationships in AI-driven warfare pose a crucial challenge to international law: ensuring that AI does not inadvertently create pathways to practical impunity for States.