The Role of Article 36 Legal Reviews Across the Military AI Assurance Lifecycle
Author: Damian Copeland
Introduction
Australia’s 2026 National Defence Strategy (NDS) recognises that new technologies, including artificial intelligence (AI) and autonomous weapon systems (AWS), are transforming military capabilities and contributing to the evolution of warfare.[1] This is evidenced by ongoing conflicts in Ukraine, Gaza, Lebanon and Iran, confirming that AI is no longer a novel technology that is peripheral to military capability. It is now embedded in critical military functions including intelligence analysis, sensor fusion, battlespace management, logistics, cyber defence, targeting support and, in some instances, AWS. For many states, including Australia, AI presents a compelling case for military advantage by enabling decision advantage over an adversary; improving the speed and scale of data processing; and enhancing the efficiency of military operations in environments characterised by strategic competition, evolving technological change and finite resources.[2] Yet the advantages of AI in the military domain also generate legal, ethical and operational risks that must be recognised and mitigated through military AI assurance mechanisms. In the case of the Australian Defence Force (ADF), this is outlined in the Policy Settings for Responsible Use of Artificial Intelligence in Defence (Responsible AI Policy), released by the Department of Defence (Defence) in March 2026, which centres on the principles of lawfulness, adherence to value-based principles and proportionate controls.[3]
It is widely recognised that AI systems are data dependent and context sensitive.[4] Their behaviour may vary according to training data, model architecture, integration choices and operational environments.[5] As a result, their outputs may be predictable and accurate in some conditions and unreliable in others. They may also shape human judgement in ways that are insufficiently visible to operators or commanders.[6] From a legal risk perspective, rather than enhancing international humanitarian law (IHL) compliance, an AI system may risk reducing compliance through opaque outputs that increase risks of civilian harm.[7]
These characteristics are especially significant in high-risk applications such as decision support and targeting. While risks are widely recognised in AWS that directly apply kinetic force, they are less well understood where AI materially influences human decision-making that bears upon use-of-force decisions. Such decisions are governed by IHL rules including distinction, proportionality and precautions in attack, and include target development and identification, intelligence assessments relevant to attack decisions, and defensive responses under severe time pressure. However, misplaced reliance may have grave humanitarian or strategic consequences. AI-enabled decision-support (AI-DSS) systems may therefore raise legal, ethical and safety questions comparable in seriousness to those associated with AWS, notwithstanding the absence of a direct weapon function. Such AI use raises the key question of how militaries can assure high-risk AI applications across their lifecycle and what role national article 36 processes play in military AI assurance.
To answer this question, it is useful to consider whether such capabilities fall within a state’s article 36 legal review obligation. As AI is recognised as an enabling technology that does not itself apply force or produce a direct military effect but enables the performance of military functions,[8] this question is not resolved by merely asking whether an AI capability is a ‘weapon’. It also concerns whether the capability, in light of its function, design and foreseeable use, is capable of supporting lawful military conduct.[9]
Article 36 requires a state party to Additional Protocol I:
[i]n the study, development, acquisition or adoption of a new weapon, means or method of warfare, to determine whether its employment would, in some or all circumstances, be prohibited by international law.[10]
While the article 36 obligation is arguably satisfied by a single determination of legality, the practical need is broader than a late-stage procurement check. Its language points to review across a sequence of acquisition stages: study, development, acquisition and adoption, and so it follows that article 36 is not deliberately confined to a one-off, late-stage assessment. Rather, it can inform a more continuous, lifecycle review process that tracks the evolution of a capability design and the conditions under which it may be used in armed conflict. The ADF’s Guide to the Legal Review of New Weapons, Means or Methods of Warfare adopts this approach.[11]
This broader interpretation of article 36 has become more compelling as states and civil society have begun to articulate broader frameworks for responsible military AI. The Global Commission on Responsible Artificial Intelligence in the Military Domain (GC REAIM) argues in its 2025 report Responsible by Design that responsible military AI assurance must be understood across the lifecycle of a system and should include legal and policy evaluation, risk assessment, testing, human–system integration, monitoring, accountability and review.[12] The report adopts the Institute of Electrical and Electronics Engineers Standards Association (IEEE-SA) AI lifecycle framework as a way of structuring these requirements from the period before system development through to review, reuse and retirement.[13] Almost in parallel, the Stockholm International Peace Research Institute (SIPRI) 2026 report on responsible procurement of military AI identifies the procurement processes as a critical mechanism by which states can implement high-level political commitments and legal obligations, but only if procurement is deliberately structured to do so.[14] Meanwhile, deliberations in the Convention on Certain Conventional Weapons Group of Governmental Experts on Lethal Autonomous Weapons Systems (CCW GGE LAWS) continue to emphasise, notwithstanding continuing debate on regulatory form, the centrality of human responsibility, accountability and compliance with IHL.[15]
These developments are valuable, but they also expose a practical implementation gap. International discussions increasingly converge around high-level principles such as human responsibility, reliability, accountability, traceability and risk mitigation. They are considerably less developed, however, on the questions that must be answered before those principles can be given practical effect: which institutions are responsible for legal and technical standards; what is required at each stage of the lifecycle; what evidence must be generated and assessed before legal conclusions can be drawn; and what legal consequences follow where those requirements are not met. The risk is that ‘responsible military AI’ remains conceptually compelling but practically opaque. For military legal advisers, and especially those engaged in article 36 processes, the question is therefore a practical one: how should legal review processes contribute to a broader assurance framework for military AI, and how should that contribution be organised across the lifecycle of AI-enabled systems?[16]
Consistent with Defence’s Responsible AI Policy,[17] this article argues that article 36 legal reviews should be understood as an integral component of the ADF’s broader AI assurance framework. They are not the only assurance mechanism that encompasses technical, organisational, procurement, testing, training and monitoring measures. However, they are an indispensable element of assurance because they provide the legal architecture through which a state determines whether a capability is inherently unlawful, whether it is lawful only under certain conditions, what safeguards are necessary for lawful use and what subsequent changes trigger further review. That role is especially significant for AI-enabled systems, where lawfulness turns not on a single design feature but on the relationship between system function, system limitations, human control arrangements, operational concept and conditions of use.
This article also addresses the relationship between lawful design and lawful use, which creates a socio-technical challenge for effective legal review. Lawfulness cannot be assessed by examining any single technical feature in isolation. A functional assessment of a military AI system requires understanding the full relationship between technical design choices, system performance in operationally realistic conditions, human cognitive and procedural controls, operator training and the institutional context in which the system is deployed. This is a socio-technical challenge as much as it is a legal one. It requires legal advisers to engage with technical evidence in legally meaningful ways, and it requires technical specialists to understand which system properties carry legal significance. Bridging that translation gap between legal requirements and technical specifications, and between technical performance and legal conclusion, is one of the central institutional challenges for military AI governance, and it is one that article 36 processes for AI-enabled systems must be structured to meet.
This article proceeds in five sections. Section 2 explains what AI assurance in the military domain requires by mapping the development of responsible AI assurance from the international, Commonwealth and Defence policies. It identifies a set of common assurance principles: lawfulness, lifecycle governance, risk-based proportionality, human responsibility and accountability, reliability and security, transparency and explainability, testing and monitoring, and meaningful human control. Section 3 then explains why article 36 legal review should be understood as a central component of that broader military AI assurance framework rather than as a narrow or final-stage weapons compliance process. Section 4 draws on the author’s functional approach to the legal review of autonomous weapon systems to show why function-based legal analysis is particularly well suited to AI-enabled and autonomous capabilities, including AWS and AI-DSS. Finally, section 5 applies that approach across the military AI lifecycle and proposes practical measures for integrating article 36 review into design, development, procurement, testing, human–system integration, operational use, tactical employment, review and retirement. The article concludes that article 36 review is indispensable to giving practical effect to Defence’s Responsible AI Policy because it converts broad commitments to lawfulness, accountability and proportionate control into concrete assurance requirements across the lifecycle of military AI.[18]
What Does AI Assurance in the Military Look Like?
This article defines AI assurance in the military as a set of legal, technical, organisational and operational measures through which a state obtains justified confidence that AI-enabled capabilities can be designed, developed, acquired, deployed, used, monitored and retired consistently with law, policy and operational requirements.[19] It is not limited to technical validation or model performance testing or satisfied by broad ethical principles alone. In the military context, AI assurance must address whether an AI system is lawful, reliable, safe, accountable, appropriately governed, operationally effective and subject to context-appropriate human control and judgement across its lifecycle.[20]
The development of AI assurance in the military context can be traced through a convergence of general AI assurance frameworks, military-specific responsible AI initiatives, and national public-sector AI assurance policies. Although these frameworks differ in legal status, institutional settings and degree of specificity, they increasingly point towards a common architecture of lifecycle assurance that includes risk-based controls, human accountability, transparency, technical robustness, testing and monitoring, and mechanisms for review when systems or circumstances change.
From an Australian perspective, the starting point is the Organisation for Economic Co-operation and Development (OECD) AI Principles, first adopted in 2019 and updated in 2024.[21] Australia was among the first countries to adopt these principles.[22] The OECD AI Principles are recognised as the first intergovernmental standard on AI to ‘promote use of AI that is innovative and trustworthy and that respects human rights and democratic values’.[23] They are structured around value-based principles and five recommendations for policymakers. The value-based principles are inclusive growth, sustainable development and wellbeing; human rights and democratic values, including fairness and privacy; transparency and explainability; robustness, security and safety; and accountability. Importantly, the OECD frames these principles across the AI system lifecycle, requiring human agency and oversight, risk management, traceability, responsible disclosure and mechanisms to override, repair or decommission systems where they risk causing harm.
These general principles have influenced the development of Australian AI governance architecture. Australia’s AI Ethics Principles, developed by the Department of Industry, Science and Resources, similarly identify human, societal and environmental wellbeing, human-centred values, fairness, privacy protection and security, reliability and safety, transparency and explainability, contestability and accountability as the normative foundation for responsible AI.[24] The Australian Government’s National Framework for the Assurance of AI in Government, released in June 2024, builds on those principles and identifies assurance as an essential part of AI governance in government, including the development, procurement and deployment of AI.[25] It states that assurance enables governments to understand expected benefits, identify risks and mitigations, ensure lawful use, understand whether AI is operating as expected, and demonstrate through evidence that AI use is safe and responsible.[26]
At the Commonwealth level, this policy architecture has become increasingly operational. In December 2025 the Australian Government’s Digital Transformation Agency (DTA) issued its updated Policy for the Responsible Use of AI in Government, which provides a framework for the accelerated and sustainable adoption of AI by Commonwealth agencies.[27] While the policy excludes Defence, it provides insight into what is required of Commonwealth agencies to develop a strategic approach to AI adoption to operationalise responsible AI use, including designating accountability for AI use cases and undertaking risk-based use-case assessments. It is organised around strategy and oversight, preparedness and operations, and AI use-case impact assessment.[28] This policy is complemented by the DTA’s AI technical standard, which translates responsible AI into practical and technical guidance. It addresses the end-to-end design, development, deployment and use of AI systems and aligns its requirements to an AI lifecycle model.[29]
Finally, the National AI Centre’s guidance for AI adoption provides a useful summary of what operational AI assurance requires in practice. It identifies six essential practices for responsible AI governance: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control.[30] The implementation guidance is directed to organisations that build or customise AI systems, use AI in complex ways, manage higher-risk use cases, or require stronger controls and oversight. It also emphasises the need for governance frameworks, clear roles, AI registers, supply-chain accountability, system-specific review, clear records, testing, incident monitoring and ongoing improvement.
For Defence these Commonwealth frameworks, despite not applying directly to military AI, are important not because they address the distinctive legal and operational questions raised by military AI but because they identify the basic institutional components of an AI assurance framework. They show that responsible AI governance is not simply a matter of principle. It requires accountable decision-makers, documented use cases, risk assessment and classification, lifecycle records, supplier information, testing evidence, monitoring processes, human oversight arrangements and review mechanisms. Those requirements are even more important in the military domain because AI systems may affect decisions concerning the use of force in targeting, detention, intelligence assessments, force protection and operational planning.
International guidance on military-specific AI assurance has developed most clearly through the REAIM process. In September 2025, the GC REAIM published its Responsible by Design report, which provides a comprehensive account of responsible military AI governance.[31] The report argues that responsibility, including ethics and law, must be integrated ‘from the earliest stage of development, through the entire AI system lifecycle’ and within the socio-technical institutions in which AI applications are embedded.[32] It emphasises that responsible development and use of AI in the military domain requires informed human decisions and context-specific approaches to designing, testing and deploying AI in ways that uphold peace and human dignity.[33] It also stresses that principles must be translated into actionable guidelines and standards for states, militaries and industry.[34]
In parallel, the REAIM summits have sought to move the discussions on AI assurance towards the concept of ‘responsible AI’ as a practical governance measure of AI-enabled military systems across their lifecycle. It recognises that risks cannot be assessed only at the point of deployment. They arise in capability design, data selection, model development, testing, system integration, human–machine interaction, procurement, operational use, monitoring, updating, reuse and retirement. For military AI, assurance must therefore be continuous, evidence based and institutionally embedded.
The 2026 REAIM Summit, held in A Coruña, Spain, emphasised the need for states to take an operationally focused direction. Its outcome document, the REAIM Pathways to Action, which was signed by Australia, identified the need to translate principles for responsible military AI into concrete measures.[35] To achieve this objective, it proposed practical steps for responsible military AI, including legal compliance, sustained human involvement, traceable accountability, risk assessment, documentation of decision-making processes, and cross-regional capacity building.[36] Although the document remains non-binding and attracted less support than previous REAIM outcome documents,[37] it confirms a broader trend: the responsible military AI agenda is moving from principles to implementation, from declarations to assurance practices, and from general language to concrete lifecycle governance.
Defence’s 2026 Responsible AI Policy follows this international trajectory. This policy states that AI technologies offer opportunities to improve accuracy, efficiency, speed and safety, but that Defence will use AI responsibly and in compliance with Australia’s domestic and international legal obligations.[38] Defence further commits to an informed, risk-based approach that preserves individual accountability for AI-enabled decisions and outcomes.[39] The policy identifies three obligations: lawfulness; adherence to values-based principles, including individual accountability, human impact, explainability, reliability and security, and mitigation of unintended bias and unintentional harm; and proportionate controls based on risk.[40]
Taken together, these frameworks suggest that military AI assurance should contain at least the following characteristics.
- Lawfulness. Military AI must comply with domestic law and international law. For the ADF, this includes the law of armed conflict, including targeting law, international weapons law, command responsibility, Commonwealth privacy, security and administrative governance obligations.
- Lifecycle governance. AI assurance must begin from development and continue through research, acquisition, testing, deployment, use, monitoring, modification, reuse and retirement. This is consistent with the OECD lifecycle approach, the GC REAIM’s ‘responsible by design’ model, the DTA technical standard and the National AI Centre’s emphasis on testing, monitoring and review.
- Risk-based assessment. Not all AI systems require the same level of assurance. Higher-risk systems, including those that influence the use of force, targeting, detention, intelligence assessments or command decisions, require higher standards and stringent evidence, human controls, oversight and legal review.
- Human responsibility and accountability. AI systems may support or shape decisions, but responsibility for military decisions must remain attributable to identifiable human actors. Accountability requires clear roles, records, traceability, command responsibility, supplier responsibility and reviewable decision-making processes.
- Technical reliability, robustness, safety and security are necessary but not sufficient. Military AI must perform reliably in the conditions in which it is intended to be used, including degraded, contested and adversarial environments. However, technical performance only becomes legally meaningful when assessed against the operational function and legal context in which the system will be employed.
- Transparency, explainability and information access are central to assurance. Defence must have sufficient information about system design, data, model limitations, confidence measures, update processes and failure modes to assess whether an AI capability can be responsibly and lawfully used. This also has procurement implications: assurance cannot be achieved where suppliers cannot or will not provide the information needed for legal and technical scrutiny.
- Testing, evaluation, verification, validation and monitoring must be continuous. Pre-deployment testing is necessary but not enough. AI systems may change over time, be used in new environments, or interact with operators in unexpected ways. Assurance must include monitoring, incident reporting, after-action review, revalidation and re-review triggers.
- Human control and human–system integration must be assessed functionally. The question is not simply whether a human is ‘in the loop’ but whether human involvement is meaningful in light of the system’s function, speed, complexity, interface, confidence signals, operator training and operational context. Human control must be designed, tested, trained and maintained.
These characteristics provide a practical perspective on what AI assurance in the military should look like. It is a lifecycle system of governance in which legal, technical, ethical, operational and organisational controls work together to create justified confidence in responsible AI use. It requires Defence to ask, at each stage of the AI lifecycle: who is accountable; what function does the AI perform; what legal and operational risks arise; what evidence is required; what controls are proportionate; what human judgement is necessary; what testing is adequate; what records must be kept; and what changes require reconsideration?
This framing also clarifies the role of article 36 legal review. Article 36 is not the whole of military AI assurance. It does not replace technical testing, procurement governance, cyber security, human factors analysis, operational doctrine, operator training or command oversight. However, it is the legal mechanism through which the ADF can determine whether AI-enabled and autonomous functions can be used consistently with international law which informs and influences the other components of the AI assurance architecture. It therefore provides the legal scaffolding of an AI assurance framework for ADF development of AWS and AI-DSS by identifying legally significant functions, specifying evidentiary requirements, translating legal risk into design and use constraints, and determining when changes in function, context or performance require further review. This legal review process is the subject of the next section.
Article 36 Legal Review as a Component of Military AI Assurance Architecture
The traditional purpose of article 36 review is well known. It requires a state party to Additional Protocol I[41] to determine whether a new weapon, means or method of warfare would be prohibited by international law in some or all circumstances. The International Committee of the Red Cross (ICRC) Guide to the Legal Review of New Weapons, Means and Methods of Warfare emphasises that the review is both substantive and procedural.[42] Substantively, it asks whether the capability is prohibited by treaty or customary law, whether it is of a nature to cause superfluous injury or unnecessary suffering, whether it is indiscriminate by nature, and whether it would otherwise contravene international law.[43] Procedurally, it requires the state to establish national mechanisms capable of obtaining the technical, operational and legal information necessary to make that determination.[44]
In conventional weapon contexts, the ADF often treats article 36 legal review as a point-in-time process conducted once, generally late in the acquisition process.[45] However, while this approach is appropriate for a static weapon or munition, e.g. a bullet, it is increasingly strained in the AI context. There are several reasons for this. First, the object of review may not be a discrete weapon in the traditional sense. AI as an enabling technology may be embedded in a sensor architecture, software, targeting system or mission-planning tool that does not itself cause an effect but materially shapes the way force is applied. Second, the capability under review may change after initial approval through software updates, changes to data inputs, model replacement, interface redesign or integration with other systems. Third, the legal analysis may depend heavily on socio-technical information that emerges only incrementally through development, testing and operational use.[46] Finally, most AI governance policies place legality as a central requirement.[47]
For these reasons, it is useful to frame article 36 review as a component of a wider military AI assurance architecture. The Defence Responsible AI Policy recognises this by requiring adherence to three policy requirements: lawfulness, adherence to value-based principles, and proportionate controls.[48] This understanding is consistent with the Responsible by Design report, which treats legal and policy evaluation, testing, monitoring, risk assessment and accountability as interlocking and continuing activities.[49] An article 36 review fits within that architecture in two ways. First, the legal analysis relies on assurance artefacts, including technical documentation, model performance information, testing outcomes, human–machine interface procedures, incident reporting and operational restrictions. Second, it generates assurance outputs, including legal risk identification, recommendations for use case constraints, compliance red lines, re-review triggers, and findings concerning the conditions under which a capability may or may not be used lawfully.
Seen in this way, article 36 reviews are not just a legal-technical validation. Technical testing cannot answer legal questions on its own. A system may perform well in benchmark conditions and still be incapable of lawful use in a particular operational context. Conversely, legal analysis that is insufficiently informed by technical and operational evidence risks being superficial and inaccurate. The challenge is therefore to ensure that legal review is embedded in a process that allows relevant evidence to be generated, scrutinised and translated into legal judgements at appropriate stages.[50]
That translation challenge is more difficult than it might appear. Legal concepts such as distinction, proportionality and precautions in attack were developed to regulate human conduct in armed conflict. Applying them to AI-enabled capabilities requires translation in both directions: from the technical output to a legal significance; and from the legal requirement to a technical specification. For example, a system’s error rate is not in itself a legal concept, but it may become legally significant where errors impact protected persons or objects, are sensitive to adversarial manipulation or occur disproportionately under operational conditions that diverge from the training environment. Conversely, a legal requirement for ‘adequate precautions’ does not translate automatically into a technical performance threshold. It requires contextual judgement about what level and type of assurance is sufficient given the system’s function, the foreseeability of harm and the operational consequences of failure.
Effective legal review of military AI must therefore engage both technical and socio-technical dimensions. This cannot be achieved by legal advisers alone. It requires structured engagement between legal, technical and operational specialists, supported by processes that generate information in legally usable forms. It also requires institutional design: review structures, evidentiary standards, documentation requirements and escalation pathways that enable legal judgements to be made on an adequate evidentiary basis and updated as information accumulates across the lifecycle. Legal advisers who lack access to relevant technical evidence cannot make meaningful legal determinations. Technical specialists who are not informed about which system properties are legally significant cannot generate the evidence that legal review requires. Addressing that structural gap is necessary for making article 36 reviews effective in the military AI context.
This approach is consistent with the text of article 36 itself. The obligation applies in the ‘study, development, acquisition and adoption’ of a weapon capability.[51] It is therefore difficult to argue that article 36 is detached from early concept design, procurement structuring or later modification. This does not mean that the law demands a full formal review at every step. It means, rather, that states can organise their processes so that legal questions are asked when they can still shape design and use, that re-review is triggered by material changes, and that a final or formal legal determination rests on a body of evidence accumulated over time. This is becoming increasingly dependent on the research and development of military AI by the private sector.
Early article 36 engagement with new technology development is particularly important in the military AI context because legal risk often arises at the intersection of technical design and the contextual use. For example, the legality of an AI-enabled target recognition system may depend not merely on model accuracy in the abstract but on whether it is used as a tool to aid human decisions or for autonomous weapon targeting. Risk may arise due to an operator’s insufficient understanding of a system’s limitations, inaccurate measures of confidence in targeting information, lack of information validation procedures, whether the system is vulnerable to adversarial deception and whether its errors create a foreseeable risk of unlawful targeting. Each of these issues is legal in significance and depends on technical and operational evidence.[52]
Accordingly, an article 36 process for military AI should include multiple legal assurance steps. As a preliminary issue, a legal review should identify the AI-enabled capability or function that requires legal review. It should identify the evidence required in order to determine compliance with IHL-specific prohibitions and restrictions and general prohibitions. It should translate legal findings into conditions of design, procurement, testing, training and use. Finally, a legal review should determine when the legality of an AI-enabled capability must be reconsidered because a change in design, use context or software may alter the original legal assessment. These functions make article 36 review not a separate legal silo but the legal foundation of a broader AI assurance framework.[53]
A Functional Approach to the Legal Review of Military AI
The author’s work on a functional approach to the legal review of AWS provides a systematic, evidence-based risk-assessment methodology for giving practical effect to article 36 review in the context of high-risk AI use cases. It is designed to enable a legal and contextual analysis of an AI application by focusing on those functions and effects that are regulated by IHL rules such as distinction, proportionality or precautions in attack.[54]
The advantage of a functional approach is that many military AI capabilities do not fit neatly into narrow article 36 concepts of ‘weapon’ and ‘means of warfare’. An AI-DSS may not itself engage a target, but it may influence how a human classifies a person or object as a lawful target or protected. An AI-DSS may also recommend target categories, priorities or weapons employed and so the legal significance of these systems lies in the ability of the human decision-maker to rely on the IHL-regulated outputs, not whether they directly cause a weapon effect. This would allow a legal review to consider a broader range of AI-DSS, for example, a system designed to recommend the status of a captured person during an article 5 tribunal during an international armed conflict.[55]
A functional approach adds substance to the traditional legal review steps and asks a series of practical questions to enable a contextual analysis of the AI system’s performance in specific operational circumstances. It aligns with the six essential practices for AI governance recommended by the Australian Government.[56] For example, what function does the AI perform? Does it identify objects, classify persons, select targets, recommend force options, or directly apply force? What are the system’s technical limitations, foreseeable failure modes and confidence boundaries in different operational contexts? What legal risks arise and what safeguards, including human control, are required if the system is to be capable of lawful use?[57]
This functional approach to legal review methodology is consistent with both article 36 and contemporary policy discussions. The ICRC guidance recognises that legal review applies to means and methods of warfare as well as to weapons.[58] Similarly, the CCW GGE LAWS rolling text identifies the characterisation of systems by reference to their capacity to select and engage targets without intervention by a human user in the execution of those tasks.[59] The Responsible by Design report, although broader in its policy ambition, similarly emphasises the need to understand AI systems across the lifecycle, including their intended role, the allocation of human responsibility and the conditions for trustworthy use.[60]
The most important contribution that the functional approach makes is that it enables a legal determination of AI-enabled systems by focusing only those functions that engage IHL obligations, and mitigates identified risks by recommending levels of human control. So where a system directly selects and engages targets, the legal review will naturally focus on the system’s capacity to comply with article 57 of Additional Protocol I requiring precautions in attack.[61] Where the system instead performs decision-support functions such as object recognition or target recommendation the review will focus on article 48 of Additional Protocol I.[62] In both cases, the question is whether the capability, in light of its function and operational conditions of use, is capable of being employed consistently with these specific IHL rules.[63]
The functional approach also helps explain why article 36 legal review must extend across the AI lifecycle. An AI-DSS’s function may remain nominally the same while its legal significance changes. A target recognition model may be retrained on new data or it may be integrated into a shorter decision loop with diminished human scrutiny, or a weapon system may shift from a constrained defensive context to a broader offensive role. These changes may alter the reliability, predictability or legal significance of the AI-enabled functions. A functional review is therefore necessarily sensitive to such lifecycle developments.[64]
Finally, the functional approach avoids the mistake of considering human control in binary terms. It recognises that human control is not a static concept and that its legal relevance depends on what risks the use of an AI system raises in any given circumstances. A functional analysis is well suited to assessing these issues by using a risk-based methodology to identify not whether a human is in the loop but whether the allocation of function between human and machine supports lawful conduct in practice.[65]
Article 36 Review Across the AI Lifecycle
The functional approach to the legal review of military AI applies a lifecycle approach to AI assurance. It recognises the need for governance inputs and measures during different stages of the AI system’s lifecycle. This directly translates into the nine stages of the IEEE-SA lifecycle framework.[66]
Before System Development
The concept stage of an AI system’s development is where many of the most important legal questions should first be identified. The GC REAIM’s Responsible by Design report places emphasis on identifying intended purpose, constraints, trade-offs, stakeholders and requirements before the technical architecture is locked in.[67] From an article 36 perspective, this stage should include an initial legal scoping review. The purpose of this exercise is not to deliver a final legal determination but to identify whether the proposed capability is likely to constitute a weapon, means or method of warfare, whether it will perform an AI function that is regulated by IHL rules, and what legal issues will need to be identified as development proceeds.[68]
At this stage, a functional approach is particularly valuable in that it is designed to inform the development of the system by private companies. Private companies developing new military technology may implement internal IHL training or engage external providers to advise on responsible development.[69] Within Defence research agencies, a military legal adviser may work with system designers, engineers and capability managers to understand the intended operational role of the proposed system and what IHL-regulated functions it will be designed to perform. If the capability is intended to classify objects for target development, the legal adviser should ask how classification will occur, what the data is used and how it is trained to achieve this, what level of confidence is expected, what information validation process is envisaged and how errors may affect downstream decisions. If the system is intended to support autonomous defensive responses, the review should ask what the threat profile is, what target set is anticipated, how tightly the use context can be bounded and what human supervision arrangements are feasible.[70]
The practical legal output of this stage should be an initial or interim legal review that identifies applicable legal rules, key legal risks, evidentiary requirements for further reviews, and timelines or triggers for additional legal consideration. It should also identify whether a particular design or use case is necessary to support lawful use. For example, the interim review may indicate key AI assurance requirements such as that the system must be capable of presenting confidence information; recording decision logs; restricting use to certain environments; or allowing human override at specified points during the planning or conduct of attacks or in cases of doubt. This early legal input is a core assurance function because it shapes the system’s requirements before later stages make redesign more difficult and costly.[71]
Research and Development
During research and development, article 36 review becomes less theoretical and progressively evidence based as technical information or testing data becomes available. The legal questions identified at the concept stage must now be examined against technical and operational realities. The GC REAIM’s Responsible by Design report places assurance checks and legal reviews within this stage, alongside data governance, model development and early validation.[72] This is practical, as a legal review at this point should influence system architecture, training methods, interface design, use cases or models and operational assumptions.
The principal task of legal advisers during development is to ensure that relevant technical and operational evidence is being generated that identifies legal risk. The required evidence will vary according to function but typically includes data provenance; known system limitations; model behaviour under expected conditions and in edge cases; foreseeable failure modes; response to adversarial conditions; system explainability or interpretability features where relevant; the proposed distribution of cognitive tasks between human users and the AI system; and finally issues of human control and accountability.[73]
For AWS, this may include evidence concerning how the system detects, tracks, selects and engages targets; how it distinguishes targets from protected persons or objects; what environmental assumptions are necessary for acceptable performance; what fail-safe or abort conditions exist; and whether there are possible gaps in human accountability. For AI-DSS, it may include evidence concerning what legally salient outputs are generated, what uncertainty or confidence measures accompany them, how operators are expected to use those outputs, whether they can interrogate them and whether the system creates foreseeable risks of automation bias or over-reliance.[74]
The functional approach assists by keeping legal analysis tied to AI-enabled or autonomous functionality that engage IHL rules. The question is not whether the model is lawful in the abstract. It is whether its performance is sufficient for the lawful performance of the relevant function in the contexts of its expected use. An AI tool that is acceptable for low-risk maintenance tasks may not be acceptable for high-risk target classification. A system with good average performance but dangerous errors in known edge cases may raise serious legal concerns if used in force-enabling functions. An article 36 review input during system development therefore involves translation between technical capability and legal significance.[75]
A further point of importance is that during research and development, testing may expose the capability as legally unsuitable for one or more of its intended roles in specific circumstances. That possibility should not be treated as a failure of the review process. It is evidence that the review is functioning properly. If development shows that a proposed system cannot achieve performance levels necessary for lawful use or does not allow the exercise of human judgement, the state should modify, constrain or abandon the relevant function. An article 36 review is not merely a mechanism for approving capabilities. It is also a mechanism for identifying when legal constraints require redesign, reduced ambition or prohibition of a proposed use.[76]
Procurement and Acquisition
Procurement and acquisition are legally significant. The Lawful by Design initiative, launched in June 2025, encourages states to include legal review and IHL requirements in their tender requirements and acquisition contracts.[77] This is reflected in SIPRI’s Responsible Procurement report, which argues that procurement is a key institutional mechanism through which states can implement political commitments and legal obligations relating to military AI, but only if procurement processes are adapted to require the relevant information, expertise and contractual controls.[78]
From an article 36 perspective, this means procurement must be informed by legal review requirements.[79] Contracting arrangements should require suppliers to provide data that is sufficient to enable a meaningful legal and technical assessment. That may include system descriptions, model and data documentation, testing results, known limitations, update policies, configuration controls and incident reporting procedures. Procurement should also allow for a state’s ability to conduct independent testing to validate supplier claims. A state cannot effectively discharge its article 36 obligations if it acquires an AI capability which is effectively opaque and cannot be independently evaluated.[80] This creates clear expectations for what militaries require from industry partners during co-development and procurement. At a minimum, procurement documentation should ensure industry provides system documentation sufficient to enable legal assessment.
Where a capability is co-developed with industry rather than commercially procured off the shelf, these requirements should be embedded in the project plan from the outset. Legal advisers must be engaged before technical performance specifications are finalised, not consulted after system architecture has already been established. Legal requirements that are not incorporated into the design from the beginning may be impossible to achieve retroactively. This connects directly to the Lawful by Design framework: legal requirements must shape technical specifications at the earliest stages of co-development, and procurement and co-development contracts are among the most important instruments through which states can operationalise their article 36 obligations in practice.
Procurement also provides an opportunity to translate legal findings into assurance requirements. If legal review has identified the need for decision audit logs, restricted use conditions, retaining human control, human override features or update notification triggers, those requirements should be embedded in procurement documentation, operational procedures and training plans. This is one of the clearest ways in which article 36 review contributes to broader AI assurance. It ensures that legal conclusions are not left as abstract advice but are a design criterion carried into acquisition structures that shape what the state actually receives and how it can lawfully be used.[81]
Testing, Evaluation, Verification and Validation
Testing, evaluation, verification and validation (TEVV) processes are critical to article 36 reviews because they provide the empirical data for determining the legality of an AI capability. The GC REAIM report identifies TEVV as a distinct lifecycle stage while also emphasising ongoing testing and monitoring during in-service life.[82] The significance is that the legality of an AI capability cannot be determined if its testing regime does not examine the specific data, models, use cases and conditions that will impact its lawful use.[83]
For this reason, the legal adviser should be concerned not only with the existence of testing but with its adequacy and relevance. In the AI context, a narrow focus on performance metrics or laboratory conditions may be misleading. Testing should reflect operationally realistic conditions, including degraded environments, enemy actions, unexpected objects, compressed timelines and human–system interaction effects.[84] For attack-related functions, legal advisers should pay particular attention to whether testing data enables legal determinations about distinction, precautions and the foreseeability of system error. For decision-support systems, the focus may be on whether operators correctly interpret outputs, whether uncertainty is communicated effectively, and whether error patterns create unacceptable risks in the decisions the system influences.[85]
Testing should also be linked to the conditions needed for legal approval. If lawful use depends on the existence of a specific operational environment, the testing regime must validate performance in that environment and identify the environmental circumstances in which performance becomes unreliable. If approval depends on human verification of certain outputs, testing must examine whether the human users are able to perform the verification role effectively. If use is limited to defensive operations against specified object classes, testing should support those specific constraints. In summary, TEVV should be designed not purely as a technical exercise but also as the evidentiary basis for legal findings and conclusions.[86]
Human–System Integration, Education and Training
The lawful use of military AI will turn on how human beings interact with the system. The GC REAIM report regards human–system integration, education and training as a distinct lifecycle stage.[87] This reflects the reality that even a technically capable system may be incapable of lawful use if operators do not understand its intended purpose, its performance limitations and when human intervention is required.
The functional approach to legal review applies a risk-based assessment of the proposed human operator’s role.[88] A legal review should consider the design of interfaces, the presentation of confidence or uncertainty information, the timing and pace of decisions, the scope for human intervention and the content of operator training programs. It should also examine known cognitive risks, including automation bias. A human decision-maker who is functionally ‘in the loop’ but presented with opaque outputs at a pace or in a format that prevents the exercise of human judgement may not provide the kind of human control on which the system’s lawfulness is assumed to depend.[89]
Operator training is therefore a critical issue. It is a precondition for lawful use where human judgement is central to legal compliance. An article 36 legal review may identify that a system is capable of lawful use only if operators are trained to understand defined limitations, verification steps, escalation triggers and circumstances requiring non-use. In this way, article 36 review contributes to assurance by specifying training and human–system integration requirements as part of the legal review report outcomes.[90]
The importance of this stage reflects a broader socio-technical approach to military AI assessment that is increasingly recognised in the academic literature. The AutoPractices Project, led by Professor Ingvild Bode, recognises the need to train operators across the lifecycle to use the interface, continuously cross-check outputs, and identify conditions that might affect or degrade operators’ ability to use the interface in compliance with system objectives.[91] Similarly, Assaad and Williams argue that AI decision-support systems introduce multiple layers of complexity into military decision-making, including increased interactivity and nonlinearity, software complexity, and dynamic complexity, requiring appropriate training and education for those operating alongside these systems.[92] Klonowska and Woodcock have cautioned against legal and regulatory approaches that draw comparisons between human and AI performance in ways that obscure the complexities of human–machine interaction. [93] They propose a human–machine interaction framework that reflects the realities of warfare, which aligns directly with the functional approach adopted in this article.
These contributions share a common insight that is directly relevant to article 36 review. The legal assessment of military AI systems can neither be confined to their technical properties nor resolved by merely identifying that a human decision-maker is formally ‘in the loop’. Lawful use depends on the quality of the socio-technical interaction between the human operator and the AI system. For article 36 purposes, this means the human–system integration stage must be treated as generating legally relevant evidence to inform a legal review. An article 36 review may need to conclude that a system is capable of lawful use only in conjunction with specific human control arrangements, specific operator training requirements and clear institutional oversight mechanisms that together constitute the conditions of lawful use. Where those conditions cannot be established or maintained, the system is not capable of lawful use, regardless of its technical performance.
Political and Strategic Oversight
Some military AI capabilities may raise strategic and political questions that should not be addressed solely at the technical or tactical level. The GC REAIM report includes political and strategic considerations as a lifecycle stage, reflecting the reality that certain capabilities may affect escalation dynamics, public legitimacy, alliance policy, or the framing of acceptable military risk.[94] This may be reflected in national military AI policies.[95] While article 36 review is not a substitute for national policy, it does contribute to this stage by clarifying the boundaries within which national policy choices must operate and by identifying where a capability’s lawful use depends on high-level constraints.
To illustrate this point, an AI-enabled defensive system may be legally supportable only within a narrowly bounded defensive envelope and under specific authorization conditions. Alternatively, an AI-DSS may be considered lawful as an analytic tool informing operational planning but not as a targeting tool. A legal review at this stage should therefore inform capability managers of the capability’s accepted use cases, its limitations, and the governance measures required to ensure compliance with both legal and national policy requirements.[96]
Operational Command and Control
Once AI systems are deployed, their lawful use is the responsibility of military commanders and system operators. At this stage, referred to as the governance stage,[97] assurance is not about prospective evaluation but about ensuring lawful use over time. The GC REAIM report emphasises ongoing monitoring, maintenance, updates, interoperability and incident reporting across the AI system lifecycle.[98] From an article 36 perspective, this means that the system performance, including operational commands, should have mechanisms for tracking, recording incidents, controlling model or software changes, and escalating potential legal concerns.
Consistent with a lifecycle approach, the legal review obligation does not end when the system is fielded. It should continue through mechanisms that monitor whether the assumptions underpinning the original legal determination remain valid. If the operational environment changes materially, if performance degrades, if unexpected failure modes emerge or if operators develop patterns of use that were not anticipated, the legal basis for continued use may need to be reconsidered. The legal advisers deployed in compliance with article 82 of Additional Protocol I will play a role in this ongoing assurance.[99] This is particularly so for AI-enabled systems that rely on software updates, changing data inputs or integration with other systems.
Tactical Employment
At the tactical level, article 36 review outputs contribute by shaping operational procedures, limitations and conditions of use.[100] System operators should trust that the AWS or AI-DSS issued to them is lawful and ensure that they operate the system lawfully within its approved use cases. That may include restrictions on mission type, environment, target set, confidence thresholds, verification requirements, abort conditions or data source quality.[101]
The functional approach is again useful because tactical legality depends on the function being performed in a specific operational context. If the system provides a recommendation relevant to target classification, the operator must know what the system limitations are and when independent validation of AI outputs is required. If the system autonomously tracks and engages incoming threats within a limited envelope, tactical doctrine must reflect the conditions on which legality depends. An article 36 review thus supports tactical assurance by ensuring that legal conclusions are translated into actionable operating parameters.
Review, Reuse and Retirement
The final IEEE lifecycle stage concerns review after use, as well as decisions on reuse, retraining, repurposing or retirement. The GC REAIM report treats this stage as one of further testing, after-action analysis and decisions about sustainment or withdrawal.[102] In the article 36 context, this stage is crucial because military AI may change after initial approval or be employed in new operational contexts that raise new legal risks not considered in previous legal reviews.
As part of a lifecycle assurance process, a legal review should identify clear re-review triggers. These may include substantial software modifications, AI model replacement, retraining on new data, extension to new missions, changes to operating environment assumptions, or evidence of significant unanticipated failure.[103] After-action reviews and incident reports should be examined for their legal significance. A capability that was lawfully reviewable for one role may not remain so if its function, context or performance profile changes.
In this regard, retirement of the hardware or software may also be legally significant. If a system is no longer capable of lawful use, whether because of technical degradation, inability to maintain assurance evidence or inability to mitigate emerging legal risks, it should not remain in service. Article 36 review contributes to AI assurance not only by facilitating lawful use but by identifying when an AWS or AI-DSS should not be used.
Conclusion
The central challenge posed by AI-enabled military capabilities is not merely technical but socio-technical: lawfulness turns not on any single design feature but on the relationship between system function, system limitations, human control arrangements, operational concept and conditions of use. That relationship creates a translation problem that is relevant throughout the AI lifecycle. Legal requirements must be converted into technical specifications; technical evidence must be interpreted in legally meaningful terms; and military acquisition processes must be structured to bridge the gap between what legal advisers need to know and what development, testing and operational use actually reveal. Addressing that translation problem by embedding article 36 review across the lifecycle is the practical challenge this article has sought to address.
This article has argued that article 36 legal reviews should be understood as an integral component of the ADF’s broader AI assurance framework, not as a narrow or final-stage compliance check. That interpretation is grounded both in the text of article 36 itself, which applies across the study, development, acquisition and adoption of a capability, and in the practical realities of AI-enabled systems that evolve through research, testing, integration and operational use. Consistent with the GC REAIM’s Responsible by Design framework, SIPRI’s analysis of responsible procurement, and Defence’s Responsible AI Policy, meaningful legal review of military AI must be continuous, evidence based and structurally embedded.
A functional approach to legal reviews provides a practical methodology for making contextual, evidence-based determinations across the AI lifecycle. By focusing legal analysis on what a system does rather than how it is characterised, it enables a legal review to track the evolution of AI-enabled capabilities as they develop, are tested and are deployed.
The socio-technical dimension is central to legal assessment. As scholars have argued, the legal and ethical assessment of military AI cannot be resolved by identifying a human decision-maker nominally in the loop. It depends on the quality of the interaction between technical design, human cognition, interface design, institutional training and operational context. For article 36 review, this means that the key questions extend beyond what the system does in controlled conditions to whether the full human–machine system, in the circumstances of actual use, is capable of controlling its use in compliance with IHL. Where those conditions cannot be established or maintained, the system is not capable of lawful use regardless of its technical performance.
A lifecycle AI assurance model does not dilute technical innovation in the military. It makes it more consequential. By engaging legal reviews earlier, with more technical evidence and across more of the research, design and testing, it transforms article 36 from a late-stage compliance formality into a substantive governance instrument. By shaping design requirements, structuring procurement obligations and specifying training and operational conditions, article 36 review converts broad commitments to lawfulness, accountability and proportionate control into concrete assurance requirements that operate throughout the lifecycle of military AI. That is how article 36 can help give practical effect to the ADF's Responsible AI Policy and contribute to a broader assurance framework consistent with both IHL and the realities of contemporary military technology.
Endnotes
[1] Australian Government, 2026 National Defence Strategy (Canberra: Commonwealth of Australia, 2026), p. 76.
[2] United Nations Institute for Disarmament Research, The Global Prism of Military AI Governance: Reflections from the 2025 Regional Consultations on Responsible AI in the Military Domain (UNIDIR, 2026), pp. 7–19.
[3] Department of Defence, Policy Settings for Responsible Use of AI in Defence (Canberra: Commonwealth of Australia, 2025).
[4] J Dorsey and M Bo, 'AI-Enabled Decision-Support Systems in the Joint Targeting Cycle: Legal Challenges, Risks, and the Human(e) Dimension', International Law Studies 106 (2025): 31.
[5] Z Assaad and E Williams, ‘Technology and Tactics: The Intersection of Safety, AI, and the Resort to Force’, Cambridge Forum on AI: Law and Governance 1, e49 (2025): 7.
[6] Ibid., p. 2.
[7] Global Commission on Responsible Artificial Intelligence in the Military Domain (GC REAIM), Responsible by Design: Strategic Guidance Report on the Risks, Opportunities, and Governance of Artificial Intelligence in the Military Domain (HCSS, 2025), pp. 13–18, 60–79.
[8] N Goussac and V Boulanin, Responsible Procurement of Military Artificial Intelligence (SIPRI, 2026), pp. 3–6, 10–9.
[9] D Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems (Brill, 2024), pp. 1–20; GC REAIM, Responsible by Design, pp. 71–79.
[10] Protocol Additional to the Geneva Conventions of 12 August 1949, and relating to the Protection of Victims of International Armed Conflicts (Protocol I) (AP I), 1125 UNTS 3 (Diplomatic Conference on the Reaffirmation and Development of International Humanitarian Law Applicable in Armed Conflicts, 1977), article 36.
[11] See Part III of Australian Defence Force, Australia’s Guide to the Legal Review of New Weapons, Means or Methods of Warfare (Department of Defence, 2024).
[12] GC REAIM, Responsible by Design, pp. 60–79.
[13] Ibid., pp. 71–79.
[14] Goussac and Boulanin, Responsible Procurement of Military Artificial Intelligence, p. vii.
[15] UN Office for Disarmament Affairs, Convention on Certain Conventional Weapons Group of Governmental Experts on Lethal Autonomous Weapons Systems: Revised Rolling Text as of 12 May 2025 (United Nations, 2025), pp. 1–8.
[16] D Copeland, ‘Article 36 Canaries in the Military AI Coalmine’, Article 36 Legal, at: www.article36legal.com/blog/article-36-canaries-in-the-military-ai-coal-mine.
[17] Department of Defence, Policy Settings for Responsible Use of AI in Defence.
[18] Protocol Additional to the Geneva Conventions of 12 August 1949.
[19] B Werner and B Shumeg, Pillars of Assured and Trusted Artificial Intelligence Enabled Systems, STO-MP-IST-210 (NATO Science and Technology Office, 2026).
[20] Context-appropriate human control and judgement is currently subject to debate by states party to the Convention on Certain Conventional Weapons in the Group of Governmental Experts meetings on Lethal Autonomous Weapons Systems. UN Office for Disarmament Affairs, Chair's Summary—First 2025 Session of the GGE on LAWS, CCW/GGE.1/2025/WP.1 (7 April 2025) paras 18–20, at: https://docs-library.unoda.org/Convention_on_Certain_Conventional_Weapons_-Group_of_Governmental_Experts_on_Lethal_Autonomous_Weapons_Systems_(2025)/CCW-GGE.1-2025-WP.1_-_Chair's_summary.pdf.
[21] Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (OECD, 2019, amended 2024), at: https://oecd.ai/en/ai-principles.
[22] Ibid.
[23] Ibid.
[24] ‘Australia’s AI Ethics Principles’, Australian Government Department of Industry, Science and Resources (website), at: www.industry.gov.au/publications/australias-ai-ethics-principles (accessed 12 May 2026).
[25] ‘National Framework for the Assurance of Artificial Intelligence in Government’, Australian Government Department of Finance (website), at: www.finance.gov.au/government/public-data/data-and-digital-ministers-meeting/national-framework-assurance-artificial-intelligence-government (accessed 12 May 2026).
[26] Ibid.
[27] Digital Transformation Agency, Policy for the Responsible Use of AI in Government (Commonwealth of Australia, 2025), at: www.digital.gov.au/ai/ai-in-government-policy.
[28] Ibid., p. 5.
[29] Digital Transformation Agency, Technical Standard for Government’s Use of Artificial Intelligence (Commonwealth of Australia, 2025), at: www.digital.gov.au/policy/ai/AI-technical-standard.
[30] ‘Essential AI Practices’, Australian Government National AI Centre (website), at: www.ai.gov.au/staying-safe-and-responsible/essential-ai-practices.
[31] GC REAIM, Responsible by Design.
[32] Ibid., p. ix.
[33] Ibid., p. ix
[34] Ibid., p. xi.
[35] Third Summit on Responsible Artificial Intelligence in the Military Domain (REAIM), REAIM Pathways to Action (A Coruña: REAIM, 2026).
[36] Ibid.
[37] The 2026 REAIM Pathways to Action was signed by 36 states, in contrast to the 2024 REAIM Blueprint for Action, which was signed by over 60 states. See Z Assaad, ‘Artificial Urgency: Reflecting on AI Hype at the 2026 REAIM Summit’, Just Security, at: www.justsecurity.org/132504/ai-hype-2026-reaim-summit.
[38] Department of Defence, Policy Settings for Responsible Use of AI in Defence, p. iv.
[39] Ibid., p. 5.
[40] Ibid., p. 6.
[41] There are presently 175 states party to Additional Protocol I. See ICRC International Human Law Database, at. https://ihl-databases.icrc.org/en/ihl-treaties/api-1977/state-parties.
[42] International Committee of the Red Cross (ICRC), A Guide to the Legal Review of New Weapons, Means and Methods of Warfare (ICRC, 2006), pp. 9–18.
[43] Ibid. See also Australian Defence Force, Australia’s Guide to the Legal Review of New Weapons; and ‘Legal Review Resources’, Article 36 Legal (website), at: www.article36legal.com/legal-reviews-explained.
[44] Ibid.
[45] Based on the author’s experience as the Director of Operations and International Law, responsible for conducting article 36 legal reviews on behalf of the Australian Government.
[46] GC REAIM, Responsible by Design, pp. 60–79; Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 47–92.
[47] Department of Defence, Policy Settings for Responsible Use of AI in Defence, p. 6.
[48] Ibid., p. 5.
[49] GC REAIM, Responsible by Design.
[50] ICRC, A Guide to the Legal Review of New Weapons, Means and Methods of Warfare, pp. 17–18.
[51] Protocol Additional to the Geneva Conventions of 12 August 1949.
[52] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 93–146; United Nations Institute for Disarmament Research, The Global Prism of Military AI Governance, pp. 13–9.
[53] GC REAIM, Responsible by Design, p. 79.
[54] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 21–46.
[55] Geneva Convention (III) Relative to the Treatment of Prisoners of War, 75 UNTS 135 (Geneva, 12 August 1949), article 5.
[56] Australian Government National AI Centre, ‘Guidance for AI Adoption Foundations’, Australian Government National AI Centre (website), at: https://www.ai.gov.au/staying-safe-and-responsible/essential-ai-practices/guidance-ai-adoption-foundations (accessed 25 June 2026): (1) Decide who is accountable, (2) Understand impacts and plan accordingly, (3) Measure and manage risks, (4) Share essential information, (5) Test and monitor, (6) Maintain human control.
[57] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, Chapter 7.
[58] ICRC, A Guide to the Legal Review of New Weapons, Means and Methods of Warfare, p. 9.
[59] Werner and Shumeg, Pillars of Assured and Trusted Artificial Intelligence Enabled Systems.
[60] GC REAIM, Responsible by Design, p. 71.
[61] Protocol Additional to the Geneva Conventions of 12 August 1949, article 57.
[62] Ibid., article 48.
[63] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 93–94.
[64] Ibid., p. 174.
[65] Ibid., p. 174.
[66] GC REAIM, Responsible by Design, p. 9.
[67] Ibid., p. 9.
[68] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, Chapter 8, refers to the ‘informative phase’.
[69] See for example ‘Article 36 Legal Compliance Reports’, Article 36 Legal, at: www.article36legal.com/compliance-reports.
[70] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 199–200.
[71] GC REAIM, Responsible by Design, p. 43.
[72] Ibid., p. 9.
[73] Ibid., pp. 26–33.
[74] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 217–219.
[75] Ibid., pp. 183–184.
[76] ICRC, A Guide to the Legal Review of New Weapons, Means and Methods of Warfare, p. 14; Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, p. 152.
[77] ‘Lawful by Design Initiative’, Article 36 Legal, at: https://www.article36legal.com/lawful-by-design.
[78] Goussac and Boulanin, Responsible Procurement of Military Artificial Intelligence, pp. 5–6.
[79] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 138–139.
[80] Ibid., pp. 129.
[81] Ibid., p. 233.
[82] GC REAIM, Responsible by Design, p. 9.
[83] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 197–199.
[84] Ibid., p. 198.
[85] Ibid., p. 32.
[86] ICRC, A Guide to the Legal Review of New Weapons, Means and Methods of Warfare, p. 14.
[87] GC REAIM, Responsible by Design, p. 10.
[88] Ibid., pp. 200–204.
[89] GC REAIM, Responsible by Design, p. 10.
[90] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 149–152.
[91] The AutoPractices Project, Strengthening Human Agency in the Military Domain: Best Practices Toolkit for Policymakers, Developers, and Users of AI Systems (Odense: Center for War Studies, University of Southern Denmark, 2026), pp.19–20.
[92] Z Assaad and E Williams, ‘Technology and Tactics: The Intersection of Safety, AI, and the Resort to Force’, Cambridge Forum on AI: Law and Governance 1, e49 (2026): 6–11.
[93] K Klonowska and T Woodcock, Rhetoric and Regulation: The (Limits of) Human/AI Comparison in Legal Debates on Military AI, ASSER Research Paper No. 2025-07 (T.M.C. Asser, 2025).
[94] GC REAIM, Responsible by Design, p. 23 (n. 5).
[95] For example, UK Ministry of Defence, JSP 936 V1.1: Dependable Artificial Intelligence (AI) in Defence (UK Ministry of Defence, 2024), p. i, at: https://assets.publishing.service.gov.uk/media/6735fc89f6920bfb5abc7b62/JSP936_Part1.pdf.
[96] D Copeland, R Liivoja and L Sanders, ‘The Utility of Weapons Reviews in Addressing Concerns Raised by Autonomous Weapon Systems’, Journal of Conflict and Security Law 28, no. 2 (2023): 285–316, 300.
[97] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, p. 227.
[98] GC REAIM, Responsible by Design, p. 47.
[99] N Jevglevskaja, International Law and Weapons Review (Cambridge University Press, 2022), p. 195.
[100] Copeland et al., ‘The Utility of Weapons Reviews’, pp. 300–304.
[101] Copeland, A Functional Approach to the Legal Review of Autonomous Weapons Systems, pp. 237–239.
[102] GC REAIM, Responsible by Design, p. 51.
[103] Ibid., p. 239.