The Article 36 question for AI drones does not begin with a dramatic battlefield scene. It begins with a file: system description, concept of operations, sensor limits, autonomy functions, abort conditions, commander controls, test data, and the legal reviewer’s uncomfortable task of deciding whether a new weapon, means, or method of warfare can be used consistently with international humanitarian law. No Geneva Convention provision says, in so many words, “autonomous weapons are prohibited.” That absence does not end the review. Article 36 of Additional Protocol I requires states party to it to determine whether the employment of a new weapon would, in some or all circumstances, be prohibited by international law, and recent legal analysis treats that obligation as applicable to autonomous weapons systems rather than as a historical formality left behind by software-defined weapons.[1]
That is the right starting point for the legal implications of AI drones in warfare. The useful question is not whether a treaty contains a neat sentence banning the machine. The useful question is whether the review file honestly shows how the system will satisfy distinction, proportionality, and precaution when it is sensing, classifying, recommending, selecting, or engaging targets under operational pressure.
Lex Machina Review usually looks at AI reliability failures in legal practice: hallucinated authorities, automation bias, brittle document review, and tools that produce outputs lawyers are then tempted to treat as verified. This article applies the same verification-first lens to a military-legal setting, where unreliable outputs do not merely embarrass counsel. They can become targeting facts.
That connection is not abstract. The July 2026 article on the YFQ-44A missile test and existing legal frameworks examined an AI-enabled autonomous drone moving from test conditions toward operational relevance. This piece asks what the legal reviewer must confront before similar systems are treated as usable in armed conflict.

A weapon can be reviewable and still be hard to use lawfully
The Lieber Institute’s March 2026 analysis supplies the cleanest frame: AI-driven autonomous weapons systems push international humanitarian law operators to their limits, making genuine compliance with distinction, proportionality, and precaution extraordinarily difficult.[1] That is a narrower and stronger point than saying all autonomous weapons are automatically unlawful. It is also more useful for an Article 36 review.
A legal review is not a product brochure with citations. It should identify the circumstances in which the system can be used, the circumstances in which it cannot, and the assumptions that must remain true for the legal conclusion to hold. If the drone can classify armored vehicles in a controlled battlespace but cannot reliably interpret human behavior around a damaged vehicle, that is not a footnote. If the operator can approve a route but cannot see the classification inputs that triggered engagement, that is not a small interface issue. If the system can be launched but cannot be recalled after new civilian-presence information arrives, the problem has moved from target recognition into the law of precautions.
Human operators also make grave mistakes. International humanitarian law was not written on the assumption that soldiers are perfect sensors or perfectly disciplined lawyers. The structural concern with AI-driven drones is different: the failure mode may be hidden inside probabilistic classification, training-data limits, sensor degradation, and autonomy timing. When those limits are not recorded before deployment, the later investigation is asked to reconstruct legal judgment from a system that may never have made one.
Distinction is where machine perception meets legal status
Distinction requires parties to an armed conflict to distinguish between civilians and combatants, and between civilian objects and military objectives. That sentence is easy to recite and hard to operationalize. It is hardest where an AI drone’s output looks deceptively legal: “person,” “vehicle,” “weapon-like object,” “pattern consistent with hostile activity.” None of those labels is, by itself, a legal status.
The International Committee of the Red Cross has warned, in its discussion of drones in armed conflict, that first-person-view drones using low-resolution analogue cameras often make it impossible for operators to distinguish lawful from unlawful targets, and that this limitation can also compromise proportionality assessments.[2] That warning matters because it is not about some remote science-fiction autonomy problem. It is about the ordinary evidentiary substrate on which targeting decisions rest: what the operator or system can actually see.

Poor image quality does not become legally adequate because a classifier assigns a confidence score. A degraded feed may erase the features that matter most: whether a person is carrying a weapon, whether the object is a tool or a rifle, whether a person is wounded, whether civilians have moved into the area, whether a vehicle is being used for military purposes or ordinary movement. The law asks about status and conduct in context. The machine often reports visual correlation.
Irregular warfare sharpens the problem. Just Security’s analysis of AI and drone warfare identifies the difficulty AI systems face in distinguishing lawful targets in irregular contexts, including risks tied to training-data bias and the inability to interpret behavioral cues.[3] That is the point at which the word “target” becomes too blunt. A person may be a fighter, a civilian, a civilian directly participating in hostilities, a person surrendering, a person fleeing danger, a person coerced into proximity, or a person whose conduct is ambiguous because the camera angle, training data, or model assumptions are poor.
Surrender is a useful test because it exposes the legal gap. A system trained to detect weapons, movement, formations, vehicles, or prior patterns of attack may not be designed to recognize a legally meaningful change in status. Hands raised, discarded weapons, stillness after injury, movement away from a position, or gestures toward civilians are not merely visual features. They are facts that require interpretation against a battlefield context. If the system cannot perceive that context, the review should say so plainly.
The same is true of civilian intent. International humanitarian law does not require a drone to read minds, and a human commander cannot do that either. But many targeting judgments depend on behavior that is ambiguous until placed into context: why a person is approaching a road, why a vehicle is stopping near a building, why a group is carrying objects, why people are moving at night. A model can be trained on patterns. It cannot thereby inherit legal competence to decide which pattern is enough.
For Article 36 purposes, the distinction question should therefore be documented in operationally specific terms. What classes of target can the system identify? At what range, altitude, weather condition, feed quality, and communications state? What does the system do with civilians, medical personnel, wounded persons, detainees, surrender signals, and mixed groups? Does it classify only objects, or does it infer legal status? Who can see the raw feed, the confidence level, and the basis for classification? A review file that answers only “human authorization required” has avoided the hard question unless it explains what the human can actually verify.
Proportionality is not a collateral-damage calculator
Proportionality is sometimes flattened into arithmetic: expected civilian harm on one side, anticipated military advantage on the other. That simplification is dangerous even before autonomy enters the discussion. The rule requires a context-sensitive judgment about whether expected incidental civilian harm would be excessive in relation to the concrete and direct military advantage anticipated. It depends on what the attacker knows or should know at the time, how reliable that information is, and whether the situation changes before the attack is executed.
AI drones can assist parts of that inquiry. Sensors may detect structures, vehicles, movement, or heat signatures. Software may estimate blast radius, line of sight, likely routes, or object proximity. Those functions can be useful. They do not settle the proportionality judgment, because the judgment is not only about physical proximity. It is about civilian risk, military advantage, uncertainty, feasible alternatives, timing, and the credibility of the information feeding the assessment.
This is where opacity becomes more than a governance complaint. Human Rights Watch’s April 2025 report on autonomous weapons and digital decision-making argues that AI black-box opacity can preclude the audit trail required for meaningful review and that fully autonomous targeting decisions cannot be meaningfully reviewed after the fact.[4] The legal significance is immediate: proportionality review depends on knowing what information was available, how it was weighed, what uncertainty existed, and why the attack proceeded. If the system cannot expose those steps, the later file may show an outcome without a legally intelligible decision path.
A commander can be wrong and still leave a reviewable record: reports received, assumptions made, warnings considered, alternatives rejected. A black-box targeting function may leave logs, but logs are not automatically reasons. Time stamps, coordinates, confidence scores, and object labels can help, yet they may not show whether the system treated uncertainty as legally significant or merely as another weighted input. That distinction matters because proportionality is not optimized prediction. It is accountable judgment under law.
The proportionality portion of an Article 36 review should therefore resist two lazy answers. The first is procurement optimism: the claim that better sensors and more training data will solve the problem in due course. Better sensors may reduce some errors, but they do not convert legal valuation into image recognition. The second is activist overstatement: the claim that any algorithmic involvement destroys proportionality analysis. That is too broad. Decision-support tools can support lawful human judgment if the human remains able to understand, challenge, and override them. The legal risk rises sharply when the system’s output becomes the judgment in practice.
Precaution turns autonomy into a control problem
Precaution is the principle that receives too little attention in casual debates about AI weapons. It is not satisfied by choosing a target carefully at the start and then letting the machine finish the sequence. International humanitarian law requires feasible precautions in attack, including attention to verification, choice of means and methods, and the duty to cancel or suspend an attack if it becomes apparent that the target is not a military objective or that the attack would be disproportionate. The Temple Law / Institute for Law, Innovation & Technology analysis identifies the difficulty this creates for lethal autonomous weapon systems: when a system decides autonomously, the obligation to cancel or suspend becomes practically fragile if new information arises after the decision process has already begun.[5]

This is not a theoretical nicety. The precaution problem asks who can interrupt the attack, on what information, within what time, and with what technical authority. If civilians enter the target area after launch, if a person begins surrendering, if the target vehicle stops beside a protected site, if communications degrade, or if the original classification is contradicted, the law does not admire the elegance of the earlier targeting process. It asks whether the attack can still be stopped or changed.
“Human in the loop” is often offered as reassurance here. It should not be accepted as a legal conclusion. The relevant questions are more granular: Is the human approving every engagement or only the mission envelope? Is the human watching the same sensor feed the system uses? Can the human see uncertainty indicators and disconfirming information? Can the human pause, redirect, or abort after the weapon has entered its terminal phase? Is there enough time to do anything other than rubber-stamp a machine-generated recommendation? A human who cannot see, understand, or stop the relevant action is not a meaningful legal control point.
Autonomy also changes where the precautionary duty must be performed. For a conventional strike, precautions may be concentrated in planning, target verification, weaponeering, and final authorization. For an AI drone that continues sensing and acting after launch, precautions must be distributed across design, testing, deployment constraints, communications architecture, operator interface, abort logic, and rules for degraded conditions. The legal review cannot stay at the level of “the commander will comply with IHL.” It must ask whether the system architecture permits the commander and operator to do so.
A credible review should identify hard stop conditions. Loss of communications may require return, loiter, or self-neutralization rather than continued attack. Sensor degradation may require disengagement from certain target classes. Conflicting classification signals may require human confirmation. Civilian-presence indicators may require abort logic that does not wait for a confidence threshold designed for object detection rather than legal protection. These are design choices, not after-action talking points.
Rules are categorical; machine learning is probabilistic
The Guardian’s June 2026 discussion of autonomous AI-powered drones usefully describes the central tension for non-specialist readers: legal and moral rules often operate through categories, while machine-learning systems tend to produce probabilistic outputs.[6] The problem is not that probability has no place in targeting. Human commanders routinely act under uncertainty. The problem is what happens when a probability score is dressed up as if it were a legal classification.
A model may report that an object is likely a military vehicle. It may report that a person’s movement is consistent with hostile activity. It may assign a confidence level to a structure classification. None of those outputs answers whether the object is a military objective, whether the person is directly participating in hostilities, whether civilians are present, whether anticipated harm is excessive, or whether new information requires suspension. Those are legal judgments made on facts, and the facts themselves may be uncertain, incomplete, or misunderstood.
There is room for bounded automation. A drone may autonomously navigate, avoid obstacles, return to base, maintain formation, detect incoming threats, or cue a human operator to possible objects of interest. Some of those functions may reduce risk if designed well. The legal pressure increases as the system moves from navigation and sensing into target selection and engagement, and increases again when human control becomes nominal rather than functional.
What an Article 36 file should not hide
Article 36 practice varies by state, and not every state applies the same review machinery. That variation makes candor more important, not less. A serious review of AI-driven drones should not merely ask whether the weapon has a lawful use in the abstract. Many weapons do. It should define the permitted use tightly enough that the legal conclusion can survive contact with actual operating conditions.
| Review issue | What the file should disclose |
|---|---|
| Sensor limits | Feed quality, range, environmental constraints, degradation behavior, and target classes that cannot be reliably identified. |
| Classification scope | Whether the system detects objects, predicts behavior, recommends targets, or infers legal status. |
| Human control | What the human can see, understand, approve, pause, redirect, or abort at each phase of the mission. |
| Auditability | What logs, model outputs, confidence scores, raw data, and decision records are available for post-strike review. |
| Precaution logic | How the system responds to new civilian information, surrender indicators, communications loss, conflicting data, and degraded conditions. |
The hardest disclosures are usually the most legally valuable. A review file should say when the system must not be used: dense civilian environments if the sensor cannot support distinction; mixed civilian-fighter settings if the model cannot interpret behavior; targets requiring surrender recognition if no such capability exists; missions requiring dynamic reassessment if communications or abort authority are inadequate; engagements where post-strike audit would be impossible because the system cannot preserve a meaningful record.
This is also where vendor assurances should be treated carefully. A claim that a system is “explainable,” “human-supervised,” or “IHL compliant” is not the same as a reviewable showing. The reviewer needs test conditions, failure modes, confusion matrices where relevant, operational constraints, interface behavior, and the system’s response to ambiguous or changing facts. If those materials are classified, they can be handled through protected channels. Classification is not an excuse for pretending the limits do not exist.
Nor should legal review be postponed until after deployment on the theory that operators will develop good practice in the field. Operators often inherit design decisions made far upstream. If the drone cannot show why it selected a target, if it cannot transmit the relevant feed, if it cannot be recalled after a certain point, or if the interface pressures the operator toward rapid approval without meaningful context, the later operator is being asked to carry legal responsibility for a system constraint that should have been confronted before fielding.
The compliance ceiling
Current AI-driven drones are not per se illegal on the sources considered here. That claim would outrun the evidence and flatten the real work of weapons review. Some autonomy can be legally unremarkable. Some autonomous functions may improve safety. Some systems may be lawful only in narrow environments, against narrow target sets, with robust human control and conservative abort rules.
The stronger conclusion is that current AI-driven drones face a compliance ceiling. Better engineering can raise parts of it: sharper sensors, more reliable communications, better logging, improved interfaces, stricter geofencing, more conservative fail-safes. But engineering alone cannot remove the central legal gap. The missing capacity is not merely object detection. It is legally relevant judgment under changing conditions: distinguishing status from appearance, reassessing proportionality as facts shift, recognizing surrender or civilian presence, and preserving meaningful human authority to cancel or suspend an attack.
An Article 36 process that ignores opacity, sensor limits, behavioral misclassification, and loss of meaningful human control is not a serious legal review. The minimum credible position is explicit disclosure of those design limits before operational use. If the system cannot reliably perceive the facts on which the law depends, the file should not translate uncertainty into compliance language. It should say what the drone cannot do.
References
- Legal Accountability for AI-Driven Autonomous Weapons, Lieber Institute, West Point, Mar. 2026
- International humanitarian law and the use of drones in armed conflict, International Committee of the Red Cross
- AI and the Future of Drone Warfare: Risks and Recommendations, Just Security
- A Hazard to Human Rights: Autonomous Weapons Systems and Digital Decision-Making, Human Rights Watch, Apr. 2025
- Lethal Autonomous Weapon Systems (LAWS): Accountability, Collateral Damage, and the Inadequacies of International Law, Temple Law, Institute for Law, Innovation & Technology
- Can autonomous AI-powered killer drones take morality onboard?, The Guardian, Jun. 2026
