ATTRIBUTION FOR AI UNDER THE LAW OF STATE RESPONSIBILITY: AN EMERGING LEGAL GAP
Introduction
Since September 2022, Russian forces have used Iranian-designed Shahed-136 autonomous drones to carry out mass strikes against civilian infrastructure in Ukraine, killing civilians and destroying power stations, residential buildings, and energy substations. The drones autonomously navigate themselves to pre-programmed coordinates; they are not guided or approved by any human operator in real time once launched. Forensic analysis of recovered fuselages identified components manufactured by companies in the United States, Japan, Switzerland, and Canada, raising the question of the accountability of the supplier states and corporations. Iran, which designed and supplied the drones, has at various points denied transferring them to Russia. Russia has denied targeting civilians. In 2024, the ICC issued arrest warrants against named commanders, including Sergei Kobylash, Sergei Shoigu, and Valery Gerasimov, for directing missile and drone strikes against civilian objects between October 2022 and March 2023. But the warrants address individual criminal responsibility. They do not resolve which state or states bear international responsibility for the conduct of the autonomous systems themselves. It is an early and concrete illustration of the attribution problem that AI-enabled autonomous systems now pose for the law of state responsibility.
The Law of State Responsibility and Attribution
The International Law Commission’s Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA), adopted in 2001, is the most authoritative codification of customary international law on state responsibility. International responsibility arises when a state’s conduct under international law infringes an international obligation. Attribution is a basic condition, as provided in the ARSIWA Articles 4 to 11. Article 4 assigns the conduct of the state’s organs, or any person or entity that is part of its official structure. This is most clearly applicable in the case of AI systems that are created and used by government bodies. Article 5 extends attribution to entities which exercise elements of governmental authority, even if not part of the formal state apparatus, which is relevant for AI, as many AI systems are built and run by private contractors rather than the state.
Article 8 refers to conduct when a person or group acts in accordance with the instructions of the state, or under its control or direction. This provision is based on the effective control standard adopted by the International Court of Justice in Nicaragua, which requires that the state must have effective control over the specific operation that is causing the harm, rather than over the entity’s overall activities. Article 9 deals with conduct which takes place without official authority, and Article 11 with conduct which is subsequently recognized and accepted by a state as its own. In principle, these provisions could apply to AI, especially Article 11, which states that a state is not allowed to disavow unauthorised conduct, but none were written with autonomous technological systems in mind.
AI and the Attribution Gap: A Core Analysis
III.I The Black Box Problem
The greatest threat to the attribution doctrine from AI is epistemological. Many AI systems, particularly those constructed with deep learning approaches, lack clarity of reasoning and explanation that can be followed. While the creators of an algorithm might have no idea how it decides to target, give financial assistance to, or suggest content for a user, the algorithm may make such decisions. This is referred to as a “black box” problem.
Attribution under international law is fundamentally a causal inquiry; it asks whether a specific act can be traced to a specific actor through a legally cognisable connection. If either the system performs an action and the reasons for it cannot be reconstructed or there is no reconstruction of the action, then there is no factual basis for the attribution. It’s difficult for states to demonstrate that the AI followed their instructions when the inputs and outputs are confused.
This situation isn’t merely a practical problem. It identifies a major missing element in the evidence-based framework on which attribution analysis relies on. The states affected will try their best to prove any of the ARSIWA attribution grounds. Lack of clarity will be a boon to responsible states who will have strong motivations to use it as a shield.
III.I
I Autonomous Systems Beyond Pre-Programmed Instructions
The second one concerns control; being able to control the AI systems beyond their intended scope of operation. Machine learning-based systems are not static sets of rules that perform a set of actions in a predictable manner. Rather, they learn, adapt, and deliver outcomes that their creators never envisioned. The tool may discover in pursuit of its programmed goal that it can accomplish these objectives better by broadening its activities, such as by reactivating dormant malware or interfering with critical services. There was no human operator or instruction from the deploying state to escalate.
This generates a basic contradiction in the law, based on human decision as a cause of action, even if there is a long chain of command. If the algorithm’s decision is influenced by real-time inputs and there is no discernible strand of human involvement that is sufficient to satisfy the attribution requirement, the algorithm would not satisfy the standard.
III.III State-Owned, State-Contracted, and Commercial AI
Attribution analysis also depends on the legal status of the person or entity that uses or operates the AI in question. Three categories are important to differentiate. First, state-owned AI, which includes systems developed, owned, and operated directly by government entities, falls most naturally under Article 4, as long as the system acts in an official capacity. Even here, however, the opacity and autonomy problems persist. Second, state-contracted AI, systems developed or operated by private entities pursuant to government contracts, engages Article 5 or Article 8. In principle, it is possible to attribute, but only if the contractor has governmental authority or the state has effective control over the specific harmful conduct. Both are high thresholds. Third, purely commercial AI, in which a government buys an off-the-shelf system, such as for surveillance, logistics or intelligence analysis, is the furthest from clear attribution, as many governments do. The developer has no governmental role, the state does not have real control over the system’s design or main decision-making processes, and Article 8’s effective control test is likely not met.
III.IV The Autonomous Propagation Problem: NotPetya as a Case Study
NotPetya was a devastating cyberattack in 2017. The United States, United Kingdom, and other governments associated it with Russia’s GRU military intelligence service. The malware was introduced via an update to a Ukrainian accounting software. It rapidly proliferated in networks in more than 50 countries, exploiting the EternalBlue exploit and credential-harvesting code. This malware was a wiper, wiping out data and estimated to have caused $10 billion in damages globally. The destruction caused by NotPetya was much greater than what occurred in Ukraine and exceeded what its creators intended. This is an example of the attribution gap that Article 8 cannot fill, and it is an example of why there is a need for uncertainty to be intentional when there are no clear rules for autonomous systems. Attribution was not based on a legal determination of control, but rather on political statements, as required under Article 8. Russia has denied any responsibility. No international court has ever dealt with the responsibility of the state for the attack. This illustrates a real challenge to meet ARSIWA’s attribution standards in the context of autonomous systems, not a complete lack of legal options.
Existing Proposals and Non-Binding Legal Frameworks
The international community has not ignored these challenges, but it has not solved them either. The UN Group of Governmental Experts (GGE) on Lethal Autonomous Weapons Systems, under the auspices of the Convention on Certain Conventional Weapons, has produced reports reaffirming that international humanitarian law continues to apply to autonomous weapons and that human responsibility cannot be delegated to machines. The 2021 GGE report upheld the concept of human accountability, but did not go as far as establishing firm standards on attribution or control thresholds. It carries persuasive authority as a statement of state practice but creates no binding legal obligations.
The Tallinn Manual 2.0 is a non-binding academic work by legal scholars and military lawyers analysing the application of existing law to cyber operations. Its commentary on autonomous systems is explicitly tentative, acknowledging that state practice remains nascent and the applicable legal standards unsettled.
The EU AI Act is the most advanced legal framework for AI regulation. It will create a risk-based classification system for the different models and applications of AI, with the most stringent obligations for high-risk systems and developers. The regulation sets out obligations such as human oversight, transparency, explainability, data governance, auditability, and reporting of incidents. It is, however, a regulation under EU law that applies to AI developers and users. It has no impact on international law. It does not apply to states defending themselves from the use of AI by other states. It cannot close any breach of the attribution problem.
Conclusion
State responsibility has been the primary tool by which international law has traditionally tried to prevent transboundary wrongdoing by states. It assumes that any wrongful act is a result of a human decision and can be traced back to a state by a clear legal link. The assumption is undermined in three ways: First, the opacity of the processes by which such systems arrive at their outputs; second, their ability to act without any state instruction; and third, the ease with which commercial deployment can shield the state from the conduct. These combined factors make it extremely hard to pinpoint any state that is deploying or controlling such systems as being responsible for transboundary wrongdoing.
States could pursue three measures as a response. First, states could update and supplement existing state responsibility practice by developing, through the United Nations, governance frameworks and attribution standards specifically applicable to autonomous systems. Second, the International Law Commission could be invited to consider adopting an optional protocol to ARSIWA addressing the attribution of wrongful acts by autonomous systems. Third, the GGE process could be used to develop human-in-the-loop norms specifically applicable to the military use of AI. If these steps are not taken soon, the current body of international law will become progressively less relevant and effective in the face of future practice in some of the most vital state activities.






Comments