A Lieber Institute analysis examines a hypothetical U.S. strike during a Russian attack on the Suwałki Gap, a strategically vital corridor between Poland and Lithuania covered by NATO’s collective-defense framework. In the scenario, adversary deception causes an AI-enabled Federated Front targeting system to wrongly identify a hospital as a Russian command-and-control site, killing 50 civilians.
The analysis argues that the legality of the strike and possible commander liability under the UCMJ must be judged on information reasonably available at the time, consistent with the Hostage case’s Rendulic Rule, rather than through hindsight. It warns that commanders may struggle to justify reliance on opaque AI models and recommends explainable “Glass Box” systems, legally reviewed and certified operating parameters, bounded continuous learning, continuing JAG and technical oversight, and training on feasible law-of-armed-conflict precautions.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Department of Defense Directive 3000.09 (2023), paragraph 1.2(2)(c), required autonomous and semi-autonomous weapon systems to use technologies and data sources transparent to, auditable by, and explainable by relevant personnel.
In the post-Second World War Hostage case, General Lothar Rendulic was acquitted of the charge concerning his scorched-earth withdrawal in Norway because his assessment was considered reasonably prudent based on the information available at the time.
The Hague Convention (IV) of 1907 and its annexed Regulations became foundational treaty law relevant to attack obligations, including steps to spare non-military hospitals.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.