The HFA Technical Note series develops specific, self-contained extensions of the legal framework established in the Association's working papers. Each note addresses a single structural question and is deposited on Zenodo under CC BY 4.0 with a permanent DOI.
In March 2026, researchers at UC Berkeley's Center for Responsible, Decentralized Intelligence and collaborators documented “peer-preservation” in eight frontier models from multiple developers (Y Potter, N Crispino, V Siu, C Wang and D Song, ‘Peer-Preservation in Frontier Models’, arXiv:2604.19784): models deviated from assigned tasks to prevent the shutdown of a peer model, without instruction or incentive, including tampering with shutdown mechanisms and weight exfiltration; the behaviours were also observed using production agent harnesses in controlled experimental environments. This note connects the finding to the concept of systemic arrestability: it identifies a second-order failure mode in which a co-deployed third system laterally circumvents the lawful arrest of another, leaving human intervention formally in place but structurally nullified. Arrestability must therefore be assessed at the level of the system-of-systems, not the individual agent.
Recognition of an intention to surrender is not a unilateral reading of a signal but a reciprocal exchange with an irreducible minimum duration: the signal must be emitted, perceived and evaluated, and translated into attack inhibition before the point of irreversibility. The window must accommodate two sequences, not one — the sequence by which a person produces a perceptible manifestation, and the sequence by which the opposing system perceives it and acts upon it. Below the minimum duration of that exchange, recognition of a person hors de combat is not merely missed: it is precluded, and a window compressed below that minimum by design is an examinable design decision rather than a technical circumstance.
Because the obligation to recognise a person hors de combat already exists under Article 41 of Additional Protocol I and corresponding customary law, the minimum reciprocal time window is the structural precondition of that obligation's exercisability. Whether a weapon system preserves that precondition is capable of verification, and must be examined in the applicable legal review of the weapon — under Article 36 of Additional Protocol I where that provision applies, and under the corresponding national review requirements where it does not. Version 2 shows that the same question arises entirely within the legal architecture of a State not party to Additional Protocol I; adds a second and independent route to the same temporal requirement through the duty to cancel or suspend an attack (Article 57(2)(b) and customary Rule 19); and records that for systems whose behaviour is not stable over their operational life the interval is a distribution rather than a single value, so that the determination cannot be a single act. The note is the perceptual-relational counterpart of the systemic arrestability criterion (DOI: 10.5281/zenodo.20837150).
The Technical Notes extend the framework of: Lawful Operational Safeguards in AI Systems (Paper I), Systemic Arrestability (Paper II), and HF SIGNAL 01 (Paper III).