The Legal Problem at the Tactical Edge

A new Atlantic Council report published in August 2026 has drawn pointed attention to an underexamined legal and command-authority problem arising from the United States military's accelerating deployment of artificial intelligence systems in denied, degraded, intermittent, and limited (DDIL) connectivity environments — the very conditions that adversaries design electronic warfare, cyber attacks, and anti-satellite capabilities to impose.

The U.S. military should presume, the report argues, that most future operations will occur in contested environments where connectivity is poor or nonexistent. That presumption carries direct consequences for legal accountability: when a networked system loses the link to a human supervisor mid-mission, who holds authority over the AI's subsequent decisions, and under what legal framework?

Digital denial in such environments may be caused by electronic warfare systems, cyber warfare, anti-space operations, and other threat vectors. The legal significance is that these same vectors — cyber attacks among them — can force AI-enabled platforms into a de facto autonomous mode that was not anticipated by the authorizing approval documentation. The gap between what a system was accredited to do and what it actually does when cut off from command may be legally consequential under both domestic acquisition law and the laws of armed conflict.

The Rickover Model and Its Limits

To address the accountability vacuum, the Atlantic Council report floats an analogy drawn from nuclear engineering. One proposed resolution is to shift from passive, compliance-based frameworks toward a more active Admiral Rickover-style model of absolute engineering accountability, under which security accreditation would move away from static, administrative checklists toward a singular, technically competent command authority.

For readers of this journal, that framing raises a threshold question: does a Rickover-style authority constitute a "responsible commander" in the sense required by international humanitarian law? The report does not resolve that question directly, but it notes that many of the benefits of AI-enabled systems ultimately turn on human decisions — when to judge a system operationally ready, when to deploy it in contested conditions, when to trust or question its outputs, and where to set the bounds of acceptable use in line with strategic priorities and under the laws of war and rules of engagement. The implication is that those human decision points are not being systematically designed into current deployment frameworks.

The problem is compounded at the acquisition level. The Maven Smart System, for example, operated for years on short-term contracts and ad hoc appropriations before being designated a formal program of record in 2026, years after its initial fielding. Fielding a capability before a program-of-record designation means it may lack the formal legal authority instruments — operational requirements documents, test and evaluation master plans, system security engineering reviews — that would ordinarily define the boundaries of permissible autonomous behavior.

Authority Gaps in Wartime Model Updates

The Atlantic Council report is equally direct about a narrower but legally concrete problem: who is authorized to update an AI model during active conflict, and on what timeline? The report recommends that operational authorities set clear timelines for model updates in peace and wartime — for example, updating and troubleshooting within two to four weeks in peacetime and twenty-four to forty-eight hours in a conflict — and that services and commands put in place policies delineating the authorities under which personnel in tactical units are allowed to update fielded AI models and what training and certifications they need.

The legal stakes here are significant. A model update that alters targeting behavior, sensor-fusion logic, or threat-classification thresholds could, in principle, change the lawfulness calculus of a system's subsequent engagements. Yet no existing U.S. statute or Department of Defense directive squarely assigns responsibility for wartime model updates to a named official with defined legal liability. The report's call for explicit policy is, in effect, a call for the legal architecture that does not yet exist.

The Broader Cybersecurity Strategy Context

The authority question sits inside a larger strategic vacuum. A companion Atlantic Council strategy paper published in January 2026 argued that equivalent to the challenges of border security and missile defense is the defense of the information and operational technology systems upon which the national security, economy, and public safety of the United States depend, and that an operational road map for defensive and offensive campaigning requires a new coordinating architecture headed by the national cyber director.

That architecture, centered on a proposed Cybersecurity Planning and Operations Council, has not yet been established. In its absence, the August 2026 report on AI in DDIL environments finds that across Department of Defense initiatives, technical goals and policy have largely outpaced the integration work needed to cultivate fielded capabilities. For lawyers specializing in the law of cyber conflict, that sentence reads as a description of a compliance gap: systems being deployed without the governance frameworks — legal authorities, rules of engagement appendices, command accountability chains — that legality requires.

The collision between accelerating AI fielding and lagging legal frameworks is not unique to the United States, but the August 2026 report's candor about the domestic dimension is unusual in a think-tank publication. Its recommendations — delineating authorities across the AI life cycle, setting explicit model-update timelines, integrating red-teaming into the full development-to-deployment pipeline — are policy prescriptions that also function as a checklist of currently unmet legal obligations. Editors of this journal will note that each item on that checklist corresponds to an area where, in the absence of clear domestic authority, the laws of armed conflict remain the default legal framework, with all of the interpretive uncertainty that entails.

Sources