8 October 2026

From Cyberspace to AI: Translating Norms of Responsible State Behaviour in Cyberspace to AI in the Military Domain

UNIDIR | Beyza Unal

Voluntary norms of responsible State behaviour in information and communications technology (ICT) security can serve as valuable frameworks for establishing future military artificial intelligence (AI) governance. While direct transfer is impractical due to AI's unique data dependencies and autonomous functions, adapting these established ICT guidelines offers a viable pathway for international security.

Multilateral discussions reveal growing convergence among states regarding the applicability of international law, civilian protection, and maintaining human judgment over the use of force. Terminology and red lines remain contested. To bridge these gaps, future frameworks must combine positive commitments like critical infrastructure protection with negative restraints on high-risk applications. Implementing practical confidence-building measures, such as AI incident reporting and emergency response mechanisms, will be essential. However, accelerating these multilateral processes requires enhanced technical cooperation and capacity-building to ensure developing nations can participate meaningfully in shaping global military AI standards as technology rapidly outpaces policy.

Comment

Translating the UN's eleven voluntary cyber norms to military artificial intelligence exposes a fundamental doctrinal friction between static defensive thresholds and dynamic, data-driven capabilities. While the UN GGE on Lethal Autonomous Weapons Systems has long sought to define human control, AI's reliance on continuous learning models defies the discrete, event-based rules of engagement typical of traditional cyber defence. This mismatch limits the utility of traditional confidence-building measures, such as the OSCE's cyber communication channels, when applied to algorithmic decision-making.

Consequently, states operating advanced systems like the US Project Maven will likely find that real-time algorithmic drift bypasses established bilateral notification protocols. Ultimately, this operational reality forces command structures utilising platforms like the British Army's Lancer program to rely on automated validation rather than manual compliance checklists.

Strategic Question for Discussion
If the deployment of systems like Project Maven accelerates algorithmic drift in active operations, does the consensus-based framework of the UN GGE on Lethal Autonomous Weapons Systems still hold, or does it break down under the pressure of real-time operational demands?
The trajectory indicates that the consensus-based model of the UN GGE will struggle to keep pace with the operational realities of deep-learning systems. As Project Maven and similar initiatives integrate real-time data feeds, the resulting algorithmic drift will likely render static, pre-negotiated red lines obsolete. Consequently, future governance is more likely to emerge from unilateral operational constraints and bilateral crisis-management protocols rather than broad multilateral treaties.
Share your assessment in the comments below.
💬
Ask Strategic Study India ×