English · Italiano · Français · Deutsch · Español · Português · Русский · 中文 · 日本語

← Back to Human Flag

Lawful Operational Safeguards in AI Systems

Surrender Recognition, Compliance Architecture, and International Humanitarian Law

Giovanni Nardacci — Founder, Human Flag Association
humanflag.org
Working Paper — V8, 20 September 2026 · Version DOI: 10.5281/zenodo.22858777


Abstract

The prohibition on attacking a person hors de combat is a rule of customary international humanitarian law, reflected in Rule 47 of the ICRC Customary IHL Study and historically expressed in Article 23(c) of the Hague Regulations. Its practical operation presupposes that an intention to surrender, where it arises, can be expressed, perceived and translated into the withholding of attack before force becomes irreversible.

This paper argues that preserving that interval — the recognition window — is not a new obligation but a condition of effectiveness of obligations that have bound parties for over a century. Three further conditions go with it, each fixed before deployment rather than in the field. The system must hold a representation of what it is engaging on which a change of protected status can operate; where no such state exists, an indication that arrives in time has nothing to act upon. The function that registers the change must not depend on the processing chain that produced the engagement decision, since the error creating the need to recognise can otherwise suppress the recognition. And reconstructability must be provided for before deployment if compliance is to remain examinable after deployment.

Where the foreseeable normal use of a system would engage persons who, in the circumstances, should be recognised as hors de combat, review must examine whether the system preserves the practical possibility of compliance. The systematic exclusion of technically achievable safeguards relevant to that question is a decision the law has the instruments to examine, and, where a procedural regime applies, one to be justified on the record there.


Notes

Version 8 refines Version 7 without altering its structure. The reconstructability condition is stated in one proposition and located in acquisition rather than investigation: a system whose architecture neither represents the relevant status nor retains the relevant events cannot be made reconstructable after the event, and for States bound by Article 36 the ICRC's guidance on legal review supports the same point. Section VII no longer repeats that material and now addresses two boundary cases instead: configurations in which no usable window exists, and systems assembled outside a conventional chain of production, where the relevant decisions — ordering construction, supplying hardware and software, ordering employment — remain identifiable and anterior.

Corrections: Rule 47 is now given as the basis of the representational condition, which was previously derived from system architecture; the machine-safety cross-reference no longer treats guarding as resting on the same temporal assumption, guarding being the contrasting case in which exposure is prevented; the description of United States legal-review procedure is stated more precisely; and a residual citation to close-in weapon system engagement sequencing has been removed.

Supersedes Version 7 (September 2026). Companion analysis: Systemic Arrestability (Paper II), Zenodo concept DOI 10.5281/zenodo.20837150.


Cite As

Giovanni Nardacci, 'Lawful Operational Safeguards in AI Systems: Surrender Recognition, Compliance Architecture, and International Humanitarian Law' (2026), Zenodo DOI 10.5281/zenodo.21932439.

Download

📄 Download PDF 📑 View on Zenodo

Keywords

International Humanitarian Law · Autonomous Weapons · AI Governance · Lawful Operational Safeguards · Surrender Recognition · Meaningful Human Control · Temporal Compression · Defence Procurement · IHL Compliance Architecture · Article 36 AP I · Article 41 AP I · Article 57 AP I


Related Work

The temporal structure analysed in this paper is not unique to IHL. For the parallel argument in civil machine-safety law, see: Systemic Arrestability: Operator Protection in Machine Safety Law When Machine Speed Exceeds Human Reaction (Paper II, 2026), Zenodo DOI 10.5281/zenodo.20837150.

The feasibility criteria developed here are applied to a candidate recognition protocol in HF SIGNAL 01 (Paper III, 2026), Zenodo DOI 10.5281/zenodo.21183137, and extended in the HFA Technical Note series.


This paper proposes an analytical framework grounded in the customary prohibition examined in Section II and in the treaty provisions that state it for the States bound by them; it does not purport to resolve disputed questions of treaty interpretation, nor to establish binding standards of conduct beyond those the cited provisions themselves impose.

Human Flag Association — Bellinzona, Switzerland