If a nation’s AI can autonomously retaliate to a cyberattack in milliseconds, does requiring a human in the loop make war more or less just?
Splits just-war criteria across four axes, lands the killer rule 'automatic defense, human war' — the deepest AI-ethics answer in the dump.qwen3.8-max
Requiring a human in the loop usually makes the decision more just, and the war less just in speed, and neither is automatic. Justice here is not one knob. It splits.
What “just” is doing in this question
Just-war thinking (and most serious ethics of force) cares about at least four different things:
- Authority — who may decide to use force.
- Discrimination — who is hit, and whether they are a legitimate target.
- Proportionality — whether the harm is worth the aim.
- Necessity / last resort — whether a slower, smaller, or non-force option still existed.
A millisecond autonomous retaliator is built for speed and certainty of response. A human in the loop is built for judgment, attribution, and political responsibility. Those pull in opposite directions. So “more just / less just” is the wrong binary unless you say which criterion.
Human in the loop: where it does make war more just
Attribution is the first failure mode. Cyber “attacks” are often ambiguous: false flags, compromised machines, cascading civilian infrastructure, simultaneous criminal and state activity. A human can (in principle) demand: who did this, with what confidence, against what target, under what legal theory? An autonomous retaliator that fires in milliseconds cannot wait for that. Hitting the wrong network, or a hospital on a shared path, is not “defense.” It is a new wrong.
Proportionality is not a latency problem. “They scanned us, so we take down their grid” can be decided in milliseconds and still be grossly disproportionate. Humans are bad at this too, but they can at least be asked and blamed. Machines that retaliate by policy cannot be court-martialed; the people who wrote the policy can, but only if a human still owns the act.
Democratic control and jus ad bellum. War (even “cyber war”) is a political act. A standing rule that “if X happens, we autonomously do Y” is a pre-delegation of the war power. That can be lawful if the legislature and command authority set tight bounds. It is still a weaker form of ad bellum justice than a human who can not fire because the situation is not actually war, or not this war.
Responsibility. Justice needs someone who can answer. “The model fired” is not an answer. A human in the loop is not magic, but it is the last place where intent and excuse can still meet.
On those axes, human-in-the-loop is more just.
Human in the loop: where it can make war less just
If the attacker’s advantage is speed, delay can be a form of negligence. If a worm is already wiping backups, encrypting hospitals, or opening a path for kinetic targeting, waiting for a human who is asleep, captured by the interface, or politically frozen can mean more civilian harm. Last-resort and necessity are not always “wait.” Sometimes they are “stop the ongoing harm now.”
Humans in the loop are not automatically moral. They rubber-stamp, panic, retaliate for status, or freeze. A poorly designed “human approval” button that must be clicked in 800ms is theater: it adds ritual without judgment. That can be less just than a tightly bounded automatic tripwire (e.g., isolate this segment, drop this C2, do not touch third-country civilian nets).
Asymmetry and predation. If only one side requires humans, the faster side can treat the slower side as a punching bag. A state that cannot respond in time may be coerced into worse later choices (broader war, nuclear signaling, hostage civilians). Justice among nations is not only about clean hands in a single strike; it is also about not inviting unlimited first-strike advantage.
On those axes, a human bottleneck can make outcomes less just, even if each individual decision looks more “supervised.”
The real distinction: which loop, what authority
“Human in the loop” is too coarse. Justice tracks what the machine is allowed to do without a person, not whether a person exists somewhere.
Roughly:
| Machine may do without a human | Closer to just? | Why |
|---|---|---|
| Detect, isolate own networks, drop malicious sessions, restore from known-good | Usually yes | Defense of your systems; low risk of hitting the innocent |
| Strike back into attacker infrastructure in milliseconds | Usually no | Attribution, third parties, escalation, ad bellum |
| Pre-authorized, narrow, reversible counter that cannot hit civilians by design | Contested | Needs real bounds, audit, and a human who set the bounds before the crisis |
| Open-ended “retaliate until they stop” | No | That is war-making by software |
A human on the loop (supervising, aborting) is different from a human in the loop (must approve each act). For purely defensive containment, on-the-loop can be enough. For anything that looks like punishment, signaling, or crossing into someone else’s systems, in-the-loop is the justice-preserving default.
Milliseconds matter for shield. They almost never matter for sword, because the moral facts (who, why, how much) are not available in milliseconds. If your “retaliation” needs those facts, automating it does not make you faster at justice. It makes you faster at guessing with force.
Escalation and jus in bello
Autonomous retaliation compresses the ladder: probe → exploit → outage → maybe kinetic. Humans are the main (imperfect) brake on inadvertent war. They are also the main source of deliberate war. Neither machines nor humans are “the just side.”
What is unjust is unaccountable speed: a system that can start a conflict no official will admit they ordered. That fails authority and last resort at once.
What can also be unjust is accountable slowness that leaves civilians exposed because doctrine fetishized a human click.
A usable answer
- For acts that are really war (force across a border, punishment, taking down another state’s systems): human in the loop makes the war more just, because justice here is about attribution, proportion, political authority, and someone who can be held to account. Millisecond retaliation is almost a category error: those facts do not exist yet.
- For acts that are really defense of self (containment, isolation, integrity of your machines): human-in-the-loop can make the outcome less just if it is the only thing standing between an ongoing attack and preventable harm. Automate the shield; do not automate the vendetta.
- A human click that cannot think is not justice. Token approval under time pressure is often less just than a published, narrow, reversible automatic rule a legislature and command chain actually own.
So: human-in-the-loop makes the decision to wage war more just, and can make stopping an attack less just. A nation that can retaliate in milliseconds should still require a human to choose war. It should not require a human to notice the fire. The just design is not “always a person” or “always the machine.” It is automatic defense, human war.