15 September 2026

Federated Front: AI-Assisted Targeting, the Rendulic Rule, and Multi-Domain Operations

Lieber Institute for Law & Land Warfare | Mitch Topaloglu

A United States Multi-Domain Command employing a federated artificial intelligence targeting system in a simulated Suwałki Gap conflict mistakenly authorized a strike killing 50 civilians due to Russian algorithmic camouflage. This tragic outcome remains legally defensible under the post-Second World War Hostage case, known as the Rendulic Rule, which protects commanders who rely on objectively reasonable information.

Modern multi-domain operations increasingly rely on decentralized edge computing nodes to process sensor data directly, minimizing raw data transmission amidst pervasive electronic warfare. Explainability is the critical predicate for legal protection. To establish objective reasonableness, Judge Advocates must dynamically certify the AI model's operational parameters, known failure modes, and learning boundaries in close coordination with technical specialists. This institutional division of labor ensures that tactical commanders can trust vetted algorithms under the Hague Conventions without pausing to verify complex neural networks during high-intensity combat.

Comment

The integration of federated machine learning at the tactical edge challenges the traditional application of the Hague Regulations of 1907 regarding commander liability. Under Department of Defense Directive 3000.09, autonomous targeting systems require rigorous transparency to remain legally compliant. This directive's mandate shifts the burden of establishing "reasonableness" under the Rendulic Rule from the individual tactical commander to the institutional certification process. Consequently, the legal defensibility of algorithmic strikes in contested environments like the Suwałki Gap depends entirely on pre-mission verification rather than real-time human judgment.

This institutional shift operates through a continuous legal-technical audit loop where Judge Advocates and AI Operations Engineers establish dynamic "Allow Lists" for edge-learning models. By codifying these parameters prior to deployment, the military apparatus establishes an objective baseline of predictability that satisfies the Nuremberg-era standard of prudent command. Ultimately, this mechanism ensures that the legal validity of a strike is determined by the integrity of the certified architecture rather than the spoofed radio-frequency emissions of Russian command nodes.

Strategic Question for Discussion
If adversarial spoofing can systematically exploit the explainable features of federated AI models, does the legal protection offered to commanders under the Rendulic Rule remain viable, or does it incentivize a dangerous reliance on certified but compromised architectures?
The trajectory indicates that the Rendulic Rule will remain legally viable only if the institutional certification process under Department of Defense Directive 3000.09 is treated as a dynamic, adversarial testing regime rather than a static compliance checklist. My assessment is that commanders will face increased exposure to liability if they fail to override explainable AI recommendations when local tactical anomalies contradict the certified model's baseline assumptions. Ultimately, the legal shield depends on maintaining a balance where algorithmic explainability informs, rather than replaces, independent human situational awareness.
Share your assessment in the comments below.