Estimated reading time: 20 minutes
A civilian who takes up a cyber capability and turns it against a party to an armed conflict loses his protection while he does so. My previous post settled when that protection comes back: it returns when he disengages, not when he merely pauses between operations. The burden of ending participation rests on the person who chose to begin it. The genuine one-off who stops, and stops for good, becomes a civilian again; the recurring participant who keeps his next operation in reserve stays exposed.
That post left a harder case for this one, and pointed to it on the way out. I argued there that a participant who walks away in person but leaves a live capability behind — a logic bomb, a standing implant primed to fire — has not withdrawn at all, because the threat he built is still running and his exposure runs with it. That case was drawn to assume a capability the participant could still reach and take down. Cyber direct participation does not always work that way: a civilian can release a capability designed to propagate and act on its own, and then find he has nothing left to take down. The difficulty this creates is not his to exploit. It is a problem for the law that has to judge him, not a licence for him to escape it.
This is the second cyber-domain post in a row, and that is deliberate. The two belong together: the first settled the rule, and this one tests it against the case most likely to break it. The question here is narrow and, I think, unanswered in the literature. When a participant has set something in motion that runs on without him, what does disengagement even require? If the opt-out test demands that he take down what he deployed, and he cannot, does the test condemn him to indefinite targetability — not through any continuing choice of his, but through the technical character of what he released?
My answer is that it does not, and that the law needs no new category to reach that result. But getting there means being precise about what disengagement is, and refusing a tempting shortcut that a leading treatment has already taken. (My previous post is Taking a Direct Part in Hostilities.)
I. The settled test and the case that strains it
Article 51(3) AP I exposes a civilian “for such time as” he takes a direct part in hostilities and no longer; the difficulty, argued out in post #25, is knowing when that participation ends. The rest of this post takes that rule as given and asks what it demands in a case #25 set aside.
What the rule already accommodates matters for that case. The ICRC Interpretive Guidance is clear that the directness of a cause is not a question of how close in time or space the harm follows the act. Parties to conflicts routinely fight through delayed means and remote ones, and the Guidance lists timer-controlled devices and computer network attacks among its examples of hostilities conducted this way (at p. 55). A cause does not become indirect because its effect is separated from the act by hours, weeks, or a continent. The same passage settles a second point the argument will need later: where the harm has not yet occurred, directness is judged by the harm a concrete act can reasonably be expected to produce, not by waiting to see what happens.
The capability that runs on is therefore not a new animal. It is a harder instance of something the law already contemplates — a means whose effects are separated from the deploying act, sometimes by a great deal. What makes it hard is not that the doctrine has never seen delayed or remote effects; it plainly has. What makes it hard is the participant’s relationship to the running capability once it is loose: whether he can still reach it, and what his protection turns on when he cannot. That is the question the rest of this post takes up.
II. Not the killer-robots question
A post about a capability that keeps operating after its deployer walks away invites an obvious misreading, so let me close it off at the start. This is not the debate about autonomous weapon systems (AWS) that purportedly select and strike targets on their own — the “killer robots” argument that has occupied the Group of Governmental Experts for years. That debate turns on how much discretion a machine may be given at the point of engagement, and it now frames the question in terms of context-appropriate human judgement and control rather than the older shorthand of a human “in the loop.” It is a serious debate. It is not this one.
It is worth being exact about why, because the reason names what makes the civilian case distinctive. The AWS debate is an argument about a variable inside a targeting architecture. Even the most autonomous system a responsible state would field operates within a structure that has already developed and validated the targets, and within constraints that responsible humans have set in advance. Whatever one thinks of where the line should fall, the staff, the target list and the legal review are the fixed backdrop, and the dispute is only over how much — if anything — may be left to the system against that backdrop. The civilian hacker who releases a self-propagating capability is not somewhere further along that same scale. He is off it entirely, because the backdrop is not there.
Set the two side by side and the contrast comes into focus. When a NATO state engages a target, it does so through an architecture. Targets are developed and validated by a targeting staff — a multidisciplinary element drawing in intelligence, operations and legal advisers — that plans, coordinates, synchronizes and assesses targeting on the commander’s behalf (AJP-3.9, at 1-21). They move through a six-phase joint targeting cycle (at 1-14 to 1-21). Target development asks not only which targets serve the objective but whether striking them would be lawful, with legal advisers consulted and validation formalised at a Target Validation Board (at 1-15 to 1-16). There is a staff, a process, a validated target list, and a chain of human responsibility running through all of it.
The civilian who looses a self-propagating capability has none of that. No staff developed his target. No board validated it. No list records it. No legal adviser reviewed it, and no one stands ready to call the thing back — least of all him, once it has spread. This is what sets the civilian case apart, and it is why the autonomy debate does not reach it. The hard problem here has nothing to do with machine discretion. It is a human who made every decision himself, at the moment of release, and then placed the consequences beyond his own reach.
III. The extension thesis, and why the law already reaches the result
One boundary before I turn to the argument. This post concerns the civilian who acts on his own account — who chose the target and made the decision to deploy. The civilian who acts under a state’s direction and control raises different questions, of membership, attribution and state responsibility, and I leave those for a later post. What follows is about the independent actor.
The most developed treatment of the running capability in the literature is Tassilo Singer’s, and it reaches the conclusion this post shares: the civilian who looses a self-operating cyber capability should not walk free while it does its work. But it gets there by a route I think mistaken, and the mistake is worth tracing, because the reader will be tempted by it too.
Call it the extension thesis. A civilian’s active moment with an autonomous cyber capability may last only seconds, while the damage arrives weeks or months later (Singer, at pp. 7—8). On a plain reading of “for such time as,” his participation ends when his action ends, so he regains protection in the interval before the harm lands — targetable only during preparation and release, and free to keep going without fear of response. Singer’s solution is to extend the relevant period from the act to the whole operation of the capability, so the civilian stays targetable for as long as the tool runs; he guards against over-reach by insisting the three cumulative criteria for direct participation must still be met (at p. 1).
I take the worry seriously. A rule that returned protection the moment a civilian released a weeks-long capability would indeed reward him for building something he no longer has to tend. But the extension is the wrong cure, for two reasons.
The first is that its premise does not hold. Singer’s autonomous capability is one that operates “without any human control,” so that human influence becomes impossible once it is running (at p. 1). That is not an accurate description of what a civilian deployer does. Control is not abolished when the capability is released; it is exercised earlier, in the choice to build and loose a thing of a certain design. The deployer who sets a self-propagating capability going has made every governing decision — what it targets, how it spreads, when it fires — before he lets go. Autonomy of operation is not absence of human control; it is human control exercised in advance and then placed out of reach. A premise that treats the running phase as a control vacuum misdescribes the very act that makes the deployer responsible.
The second reason is more fundamental, because it holds even if one grants the premise. Satisfying the elements of direct participation tells you that an act qualifies as participation. It does not tell you how long protection is lost. The Interpretive Guidance keeps these as two separate enquiries: whether an act qualifies is answered by the three cumulative criteria — threshold of harm, direct causation, belligerent nexus (at p. 46) — while how long protection is suspended is answered many pages later, in the Guidance’s treatment of temporal scope (Section VII, at p. 70). The two questions have different tests and different homes. And the qualifying enquiry is judged at the moment of the act: the Guidance requires not that harm actually materialise but that it be objectively likely — the harm reasonably expected in the prevailing circumstances (at p. 47). So Singer’s safeguard — that the three criteria must still be met — does real work for the wrong question. It confirms that releasing the capability was direct participation, judged as of release. It says nothing about duration, which is the only thing the extension was meant to fix. The elements were satisfied at the moment of release, on the expected-harm standard the Guidance sets; they do not need to keep being satisfied for the protection to stay lost, and their satisfaction at release does not by itself extend anything.
This is why I say Singer reaches the right destination on the wrong road. The civilian who looses a running capability is indeed not free to reclaim protection while it operates, but not because the participation period must be stretched to cover the tool’s activity. The duration question was never answered by the tool’s behaviour in the first place. It is answered by what the participant has or has not done to disengage, which is the subject of the next section. Singer stretches the act to reach a result the opt-out test already delivers without any stretching.
One detail confirms how much weight the extension was asked to bear. To meet the objection that his extended period could leave a civilian targetable indefinitely, Singer suggests that a civilian wishing to desist may have to inform the concerned conflict parties of the capability’s existence in order to regain protection (at p. 9, citing Boothby p. 757). But the notification requirement is not on the page cited. Boothby’s page 757 discusses disengagement in general terms; the nearest supporting material, at pages 759 to 760, requires something weaker — that a former participant take reasonable steps so that his change of status is objectively understood by the adverse party, not that he send notice of a specific tool. Singer cites those very pages elsewhere in his article (at p. 11), so this is a misplacement rather than unfamiliarity. It matters because the notification idea is doing quiet repair work: it is what stops the extended period from running forever. If that idea rests on a misread citation, the extension thesis needed a prop its own source did not supply — which is a further sign the stretch was never necessary.
IV. What disengagement requires when the capability runs on
If the tool never governed the duration of lost protection, then the running capability changes nothing about the test and everything about what the test demands. The capability’s continued operation does not, by itself, keep the participant targetable — that was Singer’s error, and the previous section took it apart. What keeps him targetable is his own failure to disengage. The capability’s state re-enters the analysis, but at a different point: not in deciding whether he has lost protection, but in deciding what disengagement now requires of him. Schmitt put the standard as well as anyone: a direct participant “remains a valid military objective until he or she unambiguously opts out” (at p. 38).
Schmitt allows two ways to opt out: an affirmative act of withdrawal, or a sustained period of not participating. That second route — dropping out by staying out long enough — does real work for the recurring striker, the civilian who acts, goes quiet for an extended period, and by that quiet lets an established pattern of participation lapse. (The true one-off is a different case: his participation ends with his single act, and, provided he left nothing running, his protection returns once his withdrawal is objectively intelligible to a diligent adversary — no notice to the enemy required, only that the facts speak for themselves. That is the ordinary working of “for such time as,” settled in my previous post.) But neither staying out nor having acted only once can end a participation that a deployed capability is still carrying on. Extended non-participation cannot end what the tool has not stopped doing. So for the case this post is about, only the affirmative branch is available: the participant must do something, and the question is what.
Where he can still reach what he deployed, the answer is straightforward, and my previous post gave it: he takes the thing down. A standing implant the deployer can still access is a threat he is still maintaining, and disengagement means switching it off. Recall is available, so recall is required. Nothing in the running of the capability extends his exposure; his own retained control does. He remains targetable not because the implant is armed but because he is choosing, by inaction, to leave it armed when he could disarm it.
The hard case is the one where he cannot reach it. He has released a self-propagating capability, control has passed out of his hands, and there is no switch left for him to throw. Here the tempting inference — Singer’s inference — is that opting out has become impossible, so the participant is either targetable forever or must be let go the moment his hands leave the keyboard. Both conclusions are wrong, and they are wrong for the same reason: they assume that disengagement means only recall. It does not. Recall is one way to disengage, available in some cases and not others. Its absence closes one route; it does not close the destination.
What disengagement requires here is that the participant make his withdrawal objectively intelligible to the party he set out to harm. He cannot pull the capability back, but he can warn the adverse party of what is coming, and he can hand over what they need to recognise and neutralise it. This is disengagement by disclosure rather than by recall, and it is demanding: it asks the participant to give up the advantage his weapon was meant to secure. That is as it should be. The burden of ending participation rests on the one who began it, and if the manner of his participation has foreclosed the easy exit, the harder exit is the one that remains, not an excuse for having no exit at all.
This standard is not invented for the occasion. Boothby argues that a former participant must take reasonable steps so that his changed status is objectively understood by the adverse party, and that in some conflicts far-reaching action may be required to achieve it (at pp. 759—760); he records draft Canadian doctrine to the same effect (at p. 759). The United States rejects the revolving door in its official statement of the law it applies: those engaged in a pattern of direct participation do not regain protection in the intervals between acts (DoD Law of War Manual, § 5.8.4.2). Read against these, disengagement by disclosure is not a novel category but the ordinary requirement of objectively verifiable withdrawal, applied to a participant whose only available proof of withdrawal is to warn and to tell.
One thing follows that matters for the participant who has done all he can. His protection turns on the act of disengagement, not on its success. A civilian who has warned the adverse party and disclosed what they need has opted out, even if the warning arrives late, the defenders are slow, and the capability does its damage anyway. Exposure tracks what he has done, not what his weapon goes on to do — because the alternative, tying his status to the tool’s behaviour, is precisely the error of letting the capability govern the law. Here Singer’s own text is instructive. He comes within reach of the right answer, allowing that a civilian might regain protection through “contravening acts of withdrawal… like providing information about the operating” capability (at p. 11). That is disclosure as disengagement, correctly identified. But he files it as a concession that limits his extension, rather than seeing it for what it is: the opt-out test doing its ordinary work, with no extension needed to house it.
The technical premise underneath all of this is not speculative. Self-propagating code escapes its intended target and cannot be pulled back once loose; that is the demonstrated character of the tool, whoever wields it. WannaCry’s spread was halted only when a researcher, not its deployer, found and triggered a kill switch, and the machines already encrypted were not thereby saved; the capability is attributed to North Korea. NotPetya, attributed to the Russian military, was built so that infected files could not be recovered at all, and did most of its damage far from its Ukrainian target. Stuxnet, conceived and deployed by nation states on the weight of the intelligence since, was engineered with precision for one kind of industrial controller and still propagated into systems across many countries. These are state operations, and I hold them apart from the civilian case for exactly that reason. They prove nothing about who deployed the capability; they prove what such a capability does once released. Documented civilian deployment of self-propagating tools at this level of sophistication remains limited, and I will not pretend otherwise. The civilian case is built not on a catalogue of civilian precedents but on the settled character of the weapons and the settled structure of the rule.
So there is one rule, and it has two applications that turn on a single fact. The test is always disengagement. Where the participant can recall what he loosed, disengagement means taking it down. Where he cannot, it means warning the adverse party and disclosing what neutralises it. The law needs no new category to reach the participant whose weapon runs on, because the duration of his exposure always turned on one thing only: what he has done to end his part, never what the weapon does after it leaves his hands.
V. Two tests for the rule
A rule is best examined at the places it looks like it might break. Two cases press on the one just set out, and neither breaks it.
The capability that fails
Suppose the capability never works. The malware is misconfigured, the logic bomb is inert, the thing the participant loosed will do nothing at all. It is tempting to say that a dud requires no opting-out, because there is nothing left to disengage from — no threat, so no burden. The temptation should be resisted, because it smuggles the tool’s state back into the governing position, and we have just spent a section removing it from there.
The deployer’s private knowledge that his capability has failed does not restore his protection. A dud and a dormant, waiting capability look identical to everyone but him. The adverse party cannot read the code’s failure from the outside, and the participant’s own certainty is not a fact the law can act on. So the case collapses into the one already answered: if he wants his protection back while the thing sits there looking live, the disengaging act is disclosure — he must make its inertness knowable, just as the deployer of a working capability must make his withdrawal knowable. What restores protection is not that the weapon happens to be harmless; it is that its harmlessness has become objectively intelligible.
There is one case where walking away is enough, and it is worth naming precisely so it is not mistaken for the first. Where the failure is manifest — the device has visibly detonated and spent itself, or the malware has run its course and been eradicated, and the adverse party can see as much — there is nothing left running as an observable matter, and no disengaging act is required. What discharges the burden is the plain exhaustion of the capability, visible to the party that would otherwise have to guard against it. But that is not the deployer trading on private knowledge. It is the intelligibility condition satisfied by the facts themselves, with no help needed from him. The dud confirms the rule from the far side: the tool’s state never governs, and here, where the state is plain to everyone, the rule asks nothing further.
The deployer who could help but will not
Take a deployer who has genuinely lost recall but could still help — he knows what he released and could hand the adverse party the means to blunt it, and refuses. He has not disengaged. The residual act was available to him, and declining it is the opposite of taking it. He remains, as to his own status, a lawful target under Article 51(3): the person who has taken a direct part and not opted out does not require, for the lawfulness of an attack upon him, that the attack promise a definite military advantage of the kind Article 52(2) demands for objects.
And yet a strike on him may be pointless. If his death would neither stop nor slow the capability that is already loose, it buys the attacker nothing. This is worth stating carefully, because two questions hide in it that must not be run together. Whether he may lawfully be attacked is one question, answered as above. Whether attacking him is worth doing is another, answered by the military value of the strike — here, close to none. The absence of advantage does not restore his protection; it only makes the exercise of the right to attack him a poor use of force. A commander who grasps that distinction will usually spend his effort on the capability rather than its now-powerless author, not because the author is protected, but because the author is beside the point.
None of this displaces the ordinary constraints on the strike itself: incidental harm to other civilians around him still counts, and proportionality still governs. And where a commander genuinely cannot tell, from the information he has, whether a participant has withdrawn or is merely between acts, the doubt rule and the duty of feasible precaution decide what he may do — matters I have addressed in my posts on the temporal scope of direct participation and the presumption of civilian status in case of doubt, and do not reopen here. One further question — whether such a deployer might be detained to induce the cooperation he withholds — belongs to the law of detention rather than the law of targeting, and I leave it there.
Conclusion
The case that looked most likely to break the rule leaves it intact. A civilian who releases a capability that runs on without him does not fall into some gap in the law, and he does not need a new legal category built to catch him. The duration of his exposure was never a function of what his weapon does after it leaves his hands. It is a function of what he has done to end his own participation — and the running of the capability changes only what ending it requires, not whether the rule applies.
That gives one rule with two settings. Where the deployer can still reach what he loosed, disengagement means taking it down. Where he cannot, it means warning the adverse party and giving them what they need to render the thing harmless. Recall is one route to the same destination, not the destination itself, which is why its absence narrows the participant’s options without ever closing them. As the analysis showed, the opt-out test was never indexed to the tool, so nothing about a self-operating capability requires the law to be rebuilt to meet it.
The rule earns its keep most often in the case where nothing is done at all. The deployer who plants his capability and goes quiet — who neither recalls it nor discloses it, but simply hides — has not opted out, and he stays exposed for as long as the thing he built keeps working. That is the ordinary case, not the exception, and it is where a commander gets his answer: the silence of a vanished deployer is not withdrawal, and it does not restore what direct participation took away.
This closes a pair. My previous post fixed the temporal rule; this one carried it to the hardest case cyber conflict offers and found it held. One assumption has run underneath the whole argument: that we know who the deployer is. Where a participant discloses in order to disengage, he names himself in the act — one thread the next post picks up. But the deployer who stays silent leaves the harder question open, and attribution in the fog of cyber conflict is the subject I turn to next.