1 September 2026

Artificial intelligence and cyberwarfare

Meer | Maryem Laghdaf

Artificial intelligence algorithms are transforming digital battlefields by automating targeted cyberattacks, generating adaptive malware, and deploying deepfakes to destabilize political institutions. Automated systems now execute complex network intrusions in hours rather than weeks, exploiting structural vulnerabilities across energy grids and financial networks while evading traditional antivirus detection. Existing legal frameworks fail to govern autonomous digital operations.

The Budapest Convention on Cybercrime and international humanitarian law lack mechanisms for resolving complex attribution challenges, where multi-jurisdictional routing masks responsible state actors. During a landmark July 2023 debate, the United Nations Security Council warned that unchecked artificial intelligence integration threatens global peace and security. Organizations such as UNESCO have promoted international ethical standards, transparency, and human oversight to mitigate adversarial attacks and prevent an unconstrained global cyber arms race. Without binding global norms, digital escalation risks becoming a permanent feature of geopolitical competition across both conventional and virtual battlefields.

Comment

The core friction in applying existing international frameworks to AI-driven cyber operations lies in the speed-of-attribution gap. Under customary international law and Article 51 of the UN Charter, state responsibility requires clear attribution before a targeted nation can invoke self-defence measures. Multi-jurisdictional automated proxy routing, however, breaks this legal chain by obfuscating origin behind compromised neutral infrastructure faster than forensic investigation can establish state sponsorship.

A similar structural mismatch occurred during the adoption of the 1907 Hague Conventions, which struggled to govern submarine warfare and aerial bombardment until post-war treaties codified new operational boundaries. Just as early 20th-century prize rules failed against unseen U-boat engagements, static treaties like the 2001 Budapest Convention on Cybercrime offer no legal leverage against autonomous algorithmic malware operating below traditional thresholds of armed attack.

Strategic Question for Discussion
Which factor presents a greater barrier to adapting international law to algorithmic warfare — the speed-of-attribution gap under UN Charter Article 51, or the lack of binding enforcement mechanisms within frameworks like the 2001 Budapest Convention on Cybercrime?
The speed-of-attribution gap presents the more immediate structural obstacle because automated proxy routing invalidates the evidentiary timeline required for lawful self-defence under Article 51. While non-binding treaties like the Budapest Convention can be renegotiated, legal frameworks remain functionally impotent if forensic consensus cannot be established before an attack cycle concludes. Consequently, the operational reality of algorithmic warfare creates a permanent delay between digital aggression and formal legal accountability.
Share your assessment in the comments below.

No comments: