Cyber weapons present a definitional problem before they present a regulatory one. International humanitarian law attaches consequences to whether a capability is a weapon, a means of warfare or a method of warfare, and cyber capabilities sit awkwardly in all three. Article 36 of Additional Protocol I requires a state party, in the study, development, acquisition or adoption of a new weapon, means or method of warfare, to determine whether its employment would be prohibited by international law — a duty whose application to software is unsettled.
Drawing a line around the cyber-weapon
Legal Considerations on Cyber-Weapons and Their Definition, published in 2014, is the Journal's direct attempt at the definitional question. Stefano Mele proposes a definition resting on three elements — context, purpose, and means or tool — and tests it against malware including Stuxnet and Shamoon, concluding that cyber-weapons are a significant and evolving threat to national security distinct from cyber-espionage, and that addressing them requires a robust legal framework and a global response. The classification is not academic. Whether the Article 36 review duty and the targeting rules are engaged at all depends on whether the capability is characterised as a weapon, means or method of warfare in the first place.
Article 36 review applied to capabilities that do not look like weapons
No More Humans? Cybernetically-Enhanced Soldiers Under the Legal Review of Article 36 pushes the review duty to its edge, asking whether brain-computer interfaces — and the soldiers using them — can be weapons, means or methods of warfare, and working through the implications under both international humanitarian law and international human rights law. The article concludes that such interfaces could enhance compliance with principles including distinction and proportionality, while raising concerns about torture and inhuman or degrading treatment and about a state's obligations toward its own soldiers. Cyber capabilities present the same structural difficulty: a review framed around a new weapon has to be discharged for systems whose effects depend heavily on the environment into which they are deployed.
Autonomy, dual use, and the argument for a new instrument
Autonomous Weapon Systems and the Inadequacies of Existing Law: The Case for a New Treaty argues that existing international humanitarian law, human rights law and weapons law are inadequate to govern systems capable of selecting and engaging targets without human intervention. Its concerns are human control over the use of force, the potential for biased algorithms, and the difficulty of holding individuals responsible; its conclusion is that a comprehensive, legally binding treaty on autonomous weapon systems is necessary.
Regulating Dual Use AI in Cyber Operations approaches the problem from the tooling side. A model trained to identify software weaknesses supports defensive patching and offensive capability development equally, and the same algorithm may serve either purpose depending on deployment context. Computer-crime statutes criminalise unauthorised access and malicious interference after harm occurs; they do not govern model development or distribution. The article works through export control — difficult to enforce against software that replicates instantly and distributes globally — along with negligence and product-liability theories, and national-security programmes that operate under classified authorities with limited transparency. It proposes four pillars: transparency about system capabilities and limitations, structured risk assessment before release, proportionate liability for reckless deployment, and international dialogue on responsible state behaviour, noting that fragmented national approaches invite regulatory arbitrage.
Payloads whose intended effect is on people rather than systems
A New Perspective on the Achievement of Psychological Effects from Cyber Warfare Payloads: The Analogy of Parasitic Manipulation of Host Behavior considers payloads whose intended effect is behavioural rather than technical, using a parasitological analogy: as parasites manipulate the behaviour of their hosts, informational payloads may influence individuals to adopt particular beliefs or actions. The article calls for research into the contextual factors that make individuals susceptible, and into countermeasures. Payloads of that kind fit poorly against a weapons-review framework organised around physical effects, and against the rules of distinction examined in Targeting in the Cyber Domain: Legal Challenges Arising from the Application of the Principle of Distinction to Cyber Attacks, which turn on identifying a military objective.
Whether the capability is a weapon, and who may lawfully be targeted by it
Measuring Autonomous Weapon Systems against International Humanitarian Law Rules puts the objection in its strongest form. Dr. Thompson Chengeta argues that autonomous weapon systems cannot satisfy distinction, proportionality and military necessity, because each depends on contextual human judgement that does not reduce to machine code, and that even a system which technically met those tests would still offend the right to dignity — which he argues requires that any decision to use lethal force against a person be taken by a person. His framing is not whether machines can outperform soldiers, but whether they should ever act as combatants at all.
From Munitions to Malware: A Comparative Analysis of Civilian Targetability in Cyber Conflict approaches targeting from the other end. Colton Matheson compares the ICRC's Interpretive Guidance with Tallinn Manual 2.0 on what conduct makes a civilian a direct participant in cyber hostilities, and for how long that status — and therefore targetability — persists. Applying both to hypothetical scenarios, he sides with the Tallinn experts on duration.
Deepfakes and the Law of Armed Conflict opens with a commander lured into an ambush by a forged surrender video, and works from there to the authentication problem synthetic media creates once the tools that once exposed fabrication no longer can. Cybersecurity and Anti-Satellite Capabilities (ASAT): New Threats and New Legal Responses takes the question into orbit: Deborah Housen-Couriel uses the Turla group's exploitation of satellite uplinks and downlinks to extract data anonymously across dozens of countries as a case in the longer history of interference with satellite communications. Legal Implications of Vulnerability Disclosure in International Conflict examines the disclosure dynamic itself — Thomas Cross notes that every use of a vulnerability risks revealing it to the victim, who may then patch it or turn the same knowledge back on the attacker.