English · Italiano · Français · Deutsch · Español · Português · Русский · 中文 · 日本語

← Back to Human Flag

Lawful Operational Safeguards in AI Systems

Surrender Recognition, Compliance Architecture, and International Humanitarian Law

Human Flag Association — Working Paper
Author: Giovanni Nardacci · Founder
humanflag.org
Working Paper — V9, 23 September 2026 · Concept DOI: 10.5281/zenodo.21932439


Abstract

The prohibition on attacking a person hors de combat is a rule of customary international humanitarian law, reflected in Rule 47 of the ICRC Customary IHL Study and historically expressed in Article 23(c) of the Hague Regulations. It operates upon recognition, and recognition is an operation that takes time. Its practical operation therefore presupposes an interval: the time within which an intention to surrender, where it arises, can be expressed, detected, assessed and translated into the withholding of attack before force becomes irreversible.

This paper argues that preserving that interval — the recognition window — is not a new obligation but a condition of effectiveness of obligations that have bound parties for over a century. The question is not whether a human being remains formally in the decision process. It is whether the interval that compliance requires remains available to any process capable of acting on the system before the outcome becomes irreversible.

Three further conditions go with the window, each fixed before deployment rather than in the field. The system must hold a representation of what it is engaging on which a change of protected status can operate; where no such state exists, an indication that arrives in time has nothing to act upon. The function that registers the change must not depend on the processing chain that produced the engagement decision, since the error creating the need to recognise can otherwise suppress the recognition. And reconstructability must be provided for before deployment if compliance is to remain examinable after deployment.

Where the foreseeable normal use of a system would engage persons who, in the circumstances, should be recognised as hors de combat, review must examine whether the system preserves the practical possibility of compliance. The systematic exclusion of technically achievable safeguards relevant to that question is a decision the law has the instruments to examine, and, where a procedural regime applies, one to be justified on the record there.


Notes

Version 9 states the criterion in temporal rather than agential terms. Section IV.C, previously headed "Compression of Human Control", is now "Temporal Asymmetry and the Closure of the Window", and the conclusion asks whether the interval that compliance requires remains available to any process external to the system, rather than whether meaningful human control has become nominal. The presence of a human in the decision process is treated as evidence bearing on that question, not as the criterion itself.

Section II.C now states expressly that the duty to refrain remains the commander's and is exercised in the field, while whether it can be exercised at all was settled earlier, when the means were chosen. The text has been tightened throughout, and two terms aligned with the vocabulary of the paper: detection latency replaces inference latency, and legal review replaces a reference to assurance processes. The cross-reference to the companion analysis gives its current title.

Supersedes Version 8 (September 2026). Companion analysis: Systemic Arrestability (Paper II), Zenodo concept DOI 10.5281/zenodo.20837150. Related work: HFA-TN-04, Reconstructability as a Design Property, which extends the design-stage analysis to post-incident reconstructability. Zenodo concept DOI 10.5281/zenodo.22275485.


Cite As

Giovanni Nardacci, 'Lawful Operational Safeguards in AI Systems: Surrender Recognition, Compliance Architecture, and International Humanitarian Law' (2026), Zenodo concept DOI 10.5281/zenodo.21932439.

Download

📄 Download PDF 📑 View on Zenodo

Keywords

International Humanitarian Law · Autonomous Weapons · AI Governance · Lawful Operational Safeguards · Surrender Recognition · Meaningful Human Control · Temporal Compression · Defence Procurement · IHL Compliance Architecture · Article 36 AP I · Article 41 AP I · Article 57 AP I


Related Work

The temporal structure analysed in this paper is not unique to IHL. For the parallel argument in civil machine-safety law, see: Systemic Arrestability: Operator Protection in Machine Safety Law When Machine Speed Exceeds Human Reaction (Paper II, 2026), Zenodo concept DOI 10.5281/zenodo.20837150.

The feasibility criteria developed here are applied to a candidate recognition protocol in HF SIGNAL 01 (Paper III, 2026), Zenodo concept DOI 10.5281/zenodo.21183137, and extended in the HFA Technical Note series.


This paper proposes an analytical framework grounded in the customary prohibition examined in Section II and in the treaty provisions that state it for the States bound by them; it does not purport to resolve disputed questions of treaty interpretation, nor to establish binding standards of conduct beyond those the cited provisions themselves impose.

Human Flag Association — Bellinzona, Switzerland