Skip to main content
Pentagon AI Assessments Create a Civilian Casualty Legal Gap
market dataSource type: independent reporting

Pentagon AI Assessments Create a Civilian Casualty Legal Gap

This analysis explains why no entity faces legal accountability for civilian harm resulting from AI-assisted military targeting, tracing the structural gap in international humanitarian law to the Pentagon's deployment of Maven Smart System and the concurrent dismantling of civilian harm mitigation infrastructure.

Updated

The uncomfortable legal answer comes first: when an AI-assisted targeting process contributes to civilian deaths, current international humanitarian law does not automatically produce a legally responsible actor. If the attack was lawful when launched — if the attacker complied with distinction, proportionality, and feasible precautions on the information reasonably available at the time — IHL generally has no liability rule for the harmful consequences that still follow. Rebecca Crootof’s 2022 account of the “actual IHL accountability gap” is useful precisely because it does not blame the gap on artificial intelligence. It identifies the older structure: IHL prohibits and punishes unlawful conduct, but it does not compensate civilians for lawful wartime harm or assign responsibility merely because the consequences were devastating.[1]

AI targeting systems make that normal gap harder to defend in practice. They move target generation faster than ordinary review capacity, leave behind data trails that may be partial or unintelligible, and distribute the relevant choices across software developers, acquisition officials, intelligence analysts, commanders, and legal advisers. The final human approval still matters. It just does not answer the next question: after a strike, who can reconstruct the chain well enough to say whether the civilian harm was lawful, unlawful, foreseeable, preventable, or simply unremedied?

Diagram of a military AI accountability chain dissolving into gaps above civilian casualty markers

Why the Obvious Defendants Fall Away

The legal chain starts with the person most visible to doctrine: the military decision-maker who approves the attack. IHL already has categories for that person’s conduct. A commander or operator may be responsible for an unlawful strike if the attack intentionally targets civilians, is launched despite expected excessive civilian harm, or fails to take feasible precautions. Software does not erase those rules. It also does not expand them into strict liability. A lawful attack can kill civilians, and IHL’s ordinary response is not to treat the commander as a tort defendant.

That distinction is easy to state and hard to live with. If a commander relies on an AI-generated target nomination, receives a confidence score or other machine output, and approves a strike after the required review, the legal question is still framed around reasonableness, knowledge, available information, and precautions at the time of attack. The later fact of civilian casualties does not by itself prove a violation. Nor does the presence of AI by itself prove recklessness.

Command responsibility narrows the route further. Senior commanders can be liable for failing to prevent or punish war crimes by subordinates when the legal elements are met. But the doctrine still needs an underlying violation and a culpable failure tied to knowledge or reason to know. A pattern of flawed AI target recommendations may become relevant evidence. It does not convert every downstream civilian death into a command-responsibility case.

Potential actorWhy accountability often fails under current law
Military operator or approving commanderIf the strike is assessed as lawful on the information available at the time, IHL generally does not impose liability for civilian harm alone.
Senior commanderCommand responsibility usually requires an underlying unlawful act and a culpable failure to prevent or punish it.
Defense contractorProcurement structures and indemnification can shift product-liability costs away from the contractor and back to the government.
Software developer or data scientistThe developer usually does not select the target, authorize the strike, or possess the battlefield context needed for IHL-specific culpability.
Civilian victim or family seeking remedyIHL supplies prohibitions and duties, but not a general compensation system for lawful incidental harm.

The contractor route looks tempting because software defects feel familiar to product-liability lawyers. If an AI system misclassifies a vehicle, corrupts a target list, fails to display uncertainty, or produces outputs no human reviewer can realistically audit, the civilian harm may look like a product failure. Crootof’s later contractor-liability analysis argues that defense contractors are often indemnified against product-liability exposure for AI system defects, shifting costs to taxpayers, service members, and foreign civilians rather than to the firms that built the tools.[2] That does not mean contractors can never face liability for fraud, contract breach, sanctions violations, or other misconduct. It means the path from civilian death to product-liability recovery is structurally blocked in the very place many non-specialists expect it to be open.

The developer is even farther away from the strike in legal terms. A developer may design a model, curate training data, tune thresholds, or build a user interface that affects how confident a targeting cell feels. But the developer normally does not know the full intelligence picture, does not make the proportionality judgment, and does not authorize force. If the later strike is unlawful, the prosecution or plaintiff still needs a theory connecting the developer’s conduct to that unlawfulness with the necessary mental state and causation. If the strike is lawful, Crootof’s underlying point returns: IHL has no general liability category for the lawful infliction of civilian harm.[1]

This is why “human in the loop” is an incomplete legal answer. Human approval may preserve the doctrinal location of the attack decision. It may also make accountability harder to assign to the toolmaker, because the contractor can point to the government’s independent targeting judgment while the government points to a process that formally retained human control. The handoff is not incidental. It is where responsibility becomes easier to describe and harder to enforce.

The Pentagon’s AI Problem Is Not Just Opacity

Opacity matters, but it is too broad a word to do the legal work by itself. Dorsey and Moffett describe AI-enabled targeting as producing a “precision paradox”: systems promise sharper identification and faster action while making after-action reconstruction more difficult when the strike goes wrong.[3] The legal problem is not that every model is mysterious. It is that the people reviewing a civilian casualty allegation may need to know which data were used, how stale they were, what confidence signals appeared, what alternatives were available, which warning was overridden, and whether the user interface made uncertainty visible at the moment of approval.

That reconstruction burden is not academic. A casualty assessment is not a debate over whether AI is impressive in the abstract. It is a file: timestamps, intelligence sources, chat logs, legal review notes, target folders, sensor feeds, contractor documentation, model versions, and the testimony of people who may have processed many targets that day. When the system accelerates the front end, the back end inherits the complexity.

Project Maven’s current scale gives that problem operational weight. CSIS reported in June 2026 that Maven Smart System had been formalized as a program of record, had a $2.3 billion fiscal year 2027 budget request, and had about 80,000 users.[4] The same analysis, drawing on reporting about the Iran war, described Maven-enabled processes as allowing roughly 1,000 targets per hour, a tenfold increase.[4] The point is not that speed is unlawful. Speed can reduce exposure for forces and may allow better use of intelligence before it decays. The legal consequence is that any review architecture built for a slower tempo can become ceremonial if it is not resourced to match the pace of target generation.

Scale produces a separate pressure. Just Security’s July 2026 legislative analysis cited Airwars reporting that 17,000 targets were generated over 40 days in Iran.[5] That figure should be handled as a monitoring-organization estimate, not as a judicial finding. Still, even as an attributed estimate, it clarifies the institutional problem. A legal review process can survive occasional uncertainty. It is less clear that it can preserve meaningful contestation when target nominations arrive in industrial volume and each one carries its own data lineage, intelligence age, collateral estimate, and human-machine interaction history.

Accuracy figures should be read with the same caution. The Just Security analysis, citing Brennan Center data, reported that Maven Smart System had been tested at 60 percent tank-identification accuracy compared with 84 percent for humans, dropping to 30 percent in snowfall.[5] Those numbers do not prove that Maven caused a particular civilian casualty. They do show why lawyers should resist treating model performance as a procurement footnote. If accuracy changes by condition, weather, object class, sensor, or theater, then the legal relevance lies in whether users were told that, whether the tool displayed uncertainty, and whether review procedures changed when performance was known to degrade.

Military command center with a digital targeting map and a broken scale of justice

Minab Is a Test Case, Not a Verdict

The Minab strike has become the obvious place to ask whether the AI-assisted targeting chain can be audited after civilian deaths. CNN reported in July 2026 that commanders bypassed warnings about outdated intelligence in connection with the strike.[6] As of July 21, 2026, the Pentagon’s final investigation into Maven’s specific role remains incomplete. That matters. It would be premature to say Maven caused the strike, that a model error produced the casualties, or that the strike was unlawful.

The restraint cuts both ways. An incomplete investigation should not be used to make the structural issue disappear. If warnings about stale intelligence were bypassed, the legal and institutional questions are concrete: who saw the warning, where did it appear, what did the system do with it, whether the legal reviewer had access to it, whether the commander understood it, and whether the post-strike assessment team can now recover the answer. Those are not anti-AI questions. They are targeting-law questions applied to a faster and more distributed process.

The broader Iran-war context is also relevant. Readers who want the jus ad bellum and operational background can place Minab alongside broader analyses of the U.S.-Iran strikes under international law and self-defense claims under the U.N. Charter. For civilian casualty accountability, however, the narrower question is enough: can the institution reconstruct the decision chain when AI helped produce targets at a pace ordinary legal review was not built to absorb?

Civilian Harm Mitigation Was the Missing Middle Layer

The legal gap becomes more durable when the institution that might notice patterns is weakened at the same time. Civilian harm mitigation and response is not a substitute for legal accountability. It does something different: it preserves expertise, collects data, investigates incidents, identifies recurring causes, and forces operational correction even where no war crime is charged. That middle layer matters most when formal liability is least likely.

Reporting on the Department of Defense Inspector General’s May 2026 findings described a civilian harm mitigation program that had been sharply reduced, with a 90 percent workforce cut and a data platform abandoned.[7] The IG report itself, DOWIG-2026-084, concluded that the Department “may not comply with its civilian casualties and harm policy — a policy required by federal law,” and identified potential compliance concerns under 10 U.S.C. §§ 113 and 130f.[8] That is a different kind of warning from a battlefield allegation. It is an institutional-capacity warning.

The timing is what gives it force. The same period in which AI-assisted targeting systems were being used at scale was also the period in which civilian harm operations reportedly ground to a halt.[7] A system that can generate far more target nominations needs more capacity for review, pattern detection, and post-strike analysis, not less. Otherwise the practical result is predictable: the military can say the strike process was lawful, the contractor can say the government made the targeting decision, the developer can say the model did not press the button, and the civilian harm office may no longer have the staff or data infrastructure to test the chain.

This is the point at which older IHL doctrine and current Pentagon administration meet. The law’s refusal to impose liability for lawful incidental harm is not new. What is new is the operational environment in which lawful-harm determinations are being made: mass target production, machine-mediated confidence, potentially degraded review capacity, and a diminished civilian harm apparatus. The gap is no longer just doctrinal. It becomes embedded in operational practice.

What Current Legislative Attention Does and Does Not Fix

Congress has noticed parts of the problem. Wilbanks and Chappell’s July 2026 analysis at Just Security mapped six Senate bills and NDAA provisions addressing military AI and civilian protection.[5] Their diagnosis is more useful than any single bill summary: the proposals did not yet create systematic AI-specific civilian harm assessments, did not require pre-deployment civilian impact analysis in the way the problem demands, and did not build a working connection between AI oversight and the CHMR framework.[5]

That legislative gap should not be overstated. AI procurement oversight, testing requirements, reporting duties, and human-control language can all matter. Comparative debates over meaningful human control in military AI show that legal systems are still trying to decide how much human judgment must remain in the targeting loop. But control language alone does not answer the casualty-assessment question. A human may remain formally responsible for approving force while no institution is practically able to trace how the target came to that human, how the tool shaped the review, and whether recurring civilian harm was detected soon enough to change operations.

Crootof’s proposed “war torts” framework offers one possible architecture outside current law: a strict-liability remedy for certain harms caused by lawful wartime acts.[1] Its importance here is analytical, not legislative. It shows what current IHL lacks. A war-torts regime would ask who should absorb the cost of lawful but harmful military action. Existing IHL usually asks a narrower question: was the act prohibited?

Pentagon AI targeting does not create a legal vacuum. The familiar IHL rules still apply, and the presence of Maven or any other system does not make a strike unlawful by itself. The sharper conclusion is narrower: AI-assisted targeting exposes a gap IHL already contains, then makes that gap more consequential through speed, scale, opacity, and institutional fragmentation.

For lawyers advising on military AI, the hard questions therefore cannot stop at model accuracy, human control, or procurement compliance. They also have to ask whether the institution can preserve the records needed for civilian casualty assessment, whether legal reviewers can see uncertainty before approval, whether degraded model performance triggers operational limits, whether contractors retain enough responsibility to care about downstream harm, and whether any civilian harm mitigation office remains capable of finding patterns after the fact.

If no existing legal actor is designed to bear the consequences of lawful civilian harm, the remaining safeguard is institutional capacity: the ability to trace, contest, learn from, and absorb harm even when no prosecution follows. Weakening that capacity while accelerating AI-assisted targeting does not make every strike unlawful. It makes non-accountability easier to operationalize.

References

  1. AI and the Actual IHL Accountability Gap, Centre for International Governance Innovation, 2022.
  2. AI-Enabled Military Contracting and the Accountability Gap, Lawfare, 2026.
  3. Warification and the Illusion of Precision, Lieber Institute West Point, May 2026.
  4. Maven Smart System analysis, Center for Strategic and International Studies, June 2026.
  5. Civilian Protection in the Age of Military AI, Just Security, July 13, 2026.
  6. CNN reporting on the Minab strike and Maven investigation, CNN, July 2026.
  7. Guardian reporting on civilian harm mitigation disruption, The Guardian, May 15, 2026.
  8. DOWIG-2026-084, Department of Defense Office of Inspector General, May 14, 2026.

Corrections & feedback

Submit corrections, flag outdated information, or provide additional market context. Comments are moderated.

Comments

Join the discussion with an anonymous comment.

Loading comments...
Blogarama - Blog Directory