The Ratifier’s Gap: How False Algorithmic Objectivity Hollowed Out Human Judgment in AI-Assisted Targeting

Ariana Amiri

Volume 2 • Issue 2

Introduction

On November 19, 2023, Israeli soldiers pulled the poet Mosab Abu Toha out of a crowd of families walking south through a checkpoint in Gaza. He had not spoken and had not shown identification, but the soldiers already knew his full legal name, because a camera had scanned the crowd and a facial recognition system had flagged him. He was blindfolded, taken across the border, interrogated, and beaten for two days before being released without charge. A soldier eventually told him the arrest had been a mistake (Frenkel).

The system that named him ran partly on Google Photos, which is not a weapons platform but the free consumer application that sorts birthday pictures. Intelligence officers had loaded a database of wanted faces into the application and found that it picked out partially obscured faces better than the dedicated military software bought alongside it (Frenkel), the use of the app surfaced through journalism, not through any disclosure by the parties involved.

An architecture built for civilian life was pointed at a captive population and used to mark people for detention, and when it erred, the error had no author. The question of who answers for those two days runs out of candidates quickly. It is not the soldier, who acted on a flag the system produced, nor the officer, who confirmed a match a machine generated, nor Google, which did not know, nor the state, whose own investigations of soldier conduct produced indictments in under one percent of complaints filed over a five-year period (Yesh Din).

The ratifier’s gap is not a gap between human and machine but a hollow inside the human role itself, more dangerous than a loss of control because from the outside it looks exactly like control being kept. And the stakes are apparent. Between October 7, 2023 and April 1, 2026, the Gaza Ministry of Health recorded 72,289 Palestinians killed, a figure still rising, with UNICEF counting at least 21,289 children among the dead. Amnesty International concluded in December 2024 that the campaign constitutes genocide, and a United Nations Commission of Inquiry reached the same conclusion in September 2025. A campaign that two international bodies have concluded is genocide was administered, in part, by people who experienced themselves as never quite deciding anything. The claim is not that they did nothing wrong, but that the law has no vocabulary for what they did, because its categories require a decision, and they performed a confirmation.

I. Bias Enters the Data and Disappears Behind Accuracy

“

The mechanisms that should assign responsibility all look for the same thing, a decision that can be located, made by an agent who can be named, at a moment that can be dated. Ratification supplies none of the three, which is why every accountability path fails in the same way.

The gap opens before any operator sits down, because it opens in the training data. Bruun and Bo (2025), writing for the Stockholm International Peace Research Institute, identify three points where bias enters a military AI system. The first is societal bias, the world’s existing inequalities mirrored in a dataset, as when skewed media archives teach a system to read dark skin as dangerous. The second arises in data processing and centers on the proxy, an indirect measure used when the thing you want to know cannot be observed. No sensor detects combatant status, so the system is given something it can detect and told to treat it as a stand-in, arms raised for surrender, a pattern of behavior for membership. The third is bias in use, where a system trained on one reality is deployed into another that has since changed, so its accuracy quietly stops meaning what it meant.

Proxies are where the ratifier’s gap is seeded, because a proxy encodes the assumptions of whoever built it, and those people were not in Gaza. The report states that patterns “such as using prepaid phone cards and moving in groups carrying weapons—could be considered proxies… for combat status. However, in some communities, using prepaid phones may be common among civilians,” and moving armed in groups may be routine practice “in ceremonial or religious festivities, or for hunting animals” (Bruun and Bo 2025).

The proxies used in Gaza did not come from nowhere. Yossi Sariel, who commanded Unit 8200 and was earlier head of intelligence for the IDF’s central command, set out the design in a book published under a pen name, describing models built on features like “people who are with a Hezbollah member in a WhatsApp group, people who get new cellphones every few months, those who change their addresses frequently” (Sariel, quoted in Davies). Set that beside what his own officers said afterward: “In war, Palestinians change phones all the time. People lose contact with their families, give their phone to a friend or a wife, maybe lose it” (Abraham). The behavior Sariel wrote down as an indicator of enemy status is the behavior a civilian population produces under bombardment. The proxy did not fail to describe Gaza, it described Gaza precisely, and then labeled it hostile.

The assumptions about phones are the most consequential case. Israel’s Lavender system scored a person’s likelihood of being a militant partly on phone and social-media metadata, while a companion program tracked a listed man’s phone and alerted an officer when he entered his family home so the house could be bombed. It was called Where’s Daddy?, a question a child asks, and the software was named for the moment it was built to exploit. Both systems assume one phone corresponds to one person, an assumption that holds in the affluent societies where consumer tracking was designed, but collapses in Gaza. An officer described the most common error: the target “gave [his phone] to his son, his older brother, or just a random man. That person will be bombed in his house with his family. This happened often” (Abraham).

The demographic reality underneath is a matter of public record. Before the war, the Palestinian Central Bureau of Statistics reported individual smartphone ownership among Gazans aged ten and older at fifty-eight percent, against overall cellular ownership of sixty-nine percent (PCBS). That gap is the statistical shape of phone-sharing. A device in Gaza is a family resource passed between hands, not a badge of identity as it is in the West, and a system that treats it as identity will kill the wrong holder (HRW).

Confirmation that this is a Western-data problem rather than an Israeli one comes from the United States military itself. Captain Tyrese Bender, writing in the Army’s Military Intelligence Professional Bulletin, warns that “AI bias in military targeting operations may lead to high rates of misidentification in non-Western environments, where U.S.-centric data can skew results,” and points to Israel’s targeting in Gaza as the demonstration (Bender). When an active-duty American officer names the same failure that Palestinian victims and human rights researchers describe, the pattern stops being one side’s grievance and becomes structural.

The same narrowness appears at the moment the law most absolutely protects. SIPRI’s experts found that a system trained to detect surrender only as arms held above the head “may risk overlooking alternative and culturally specific signs of surrender” (Bruun and Bo 2025). A person trying to give up in the wrong idiom is, to the machine, not a person trying to give up, and the experts’ conclusion was categorical. It “was broadly agreed that AI-AWS, which are not designed to ‘recognize’ culturally specific ways of surrendering, could not be used to attack humans in accordance with the principle of distinction.” Not that such systems should be used carefully, but that they cannot lawfully be used against people at all.

Disability is another blind spot built into the data. Behavioral threat detection is trained on data that rarely includes people with psychosocial, intellectual, or sensory impairments, so the system reads their behavior against a baseline they were never part of. A deaf man who does not stop when ordered, an autistic teenager who shouts under stress, a man with a head injury who does not raise his arms: each reads to a classifier as refusal, and in a war where the share of people with disabilities rises from sixteen to thirty percent, the consequences compound (Bruun and Bo 2025). The population a system is least equipped to read is the population the war itself keeps producing, so every strike enlarges the category the machine cannot see.

Testing converts bias into a credential rather than eliminating it. The Israeli military checked a sample of Lavender’s output, found the system was right about ninety percent of the time when it linked a person to Hamas, and on that basis approved it for sweeping use (Abraham). The number corrected nothing, it carried a ten percent error rate into a process whose errors are dead families. What these systems produce is a statistical correlation, an estimate of how likely it is that a person or object is a lawful target. But law asks for judgment about a specific situation, and a correlation cannot supply that. Ninety percent reads like a finding, and institutions trust findings. A clean number does not kill anyone by itself. It kills by disarming the person whose job was to doubt it.

II. False Objectivity Converts the Judge into a Ratifier

The conversion of judge to ratifier happens in three movements. When a system’s output presents itself as neutral fact, the operator has no visible reason to doubt it. Without doubt, deciding collapses into confirming. And because a confirmer never exercised judgment, no one can be held accountable for a decision that was never made.

The operators described the conversion themselves, as personnel reviewing Lavender stated that they would invest only twenty seconds per target while verifying dozens a day, with the only check being that the target was a man (Abraham). One officer put the reduction exactly, recalling “I had zero added value as a human, apart from being a stamp of approval.” The most revealing testimony was from an officer describing a day when the pace of strikes had slowed: “One day, totally of my own accord, I added something like 1,200 new targets to the [tracking] system… In retrospect, it seems like a serious decision I made. And such decisions were not made at high levels” (Abraham). The moment of judgment was invisible to the judge while he was exercising it. He experienced adding 1,200 people to a kill pipeline as workflow, in the way one refills a queue.

The strongest objection to this account is empirical, and answering it makes the argument stronger. Shereshevsky, Shandler and Gross ran an experiment testing how willing people were to approve a strike based on where the intelligence came from. Approval rates were higher when the source was a human intelligence officer than when it was a decision support system (Shereshevsky).

If humans are actually averse to machines, how can the ratifier’s gap be real? Because the gap does not require operators to trust the machine, it requires only that the system deny them the conditions under which distrust could do any work. Aversion is a readiness to check, and checking requires time and access to the evidence underneath the recommendation, neither of which the Gaza system supplied. An operator with twenty seconds and a name on a screen has no raw intelligence to interrogate and no minutes in which to interrogate it, so whatever skepticism they feel has nothing to grip; their aversion is not overcome but disabled. Shereshevsky’s own experiment shows the mechanism: “providing participants with more detailed information eliminated the gap between the groups.” People engage with evidence when they are given it and cannot engage when they are given a score and a stopwatch. The aversion finding does not refute the thesis but identifies its hinge: the problem was never that humans are credulous, but that the system was built to make human skepticism inoperable.

The system was intentionally engineered that way and the architect wrote the design down. Sariel’s book describes constructing a target machine on “big data” that a human brain could not process, then names the obstacles: “There is a human bottleneck for both locating the new targets and decision-making to approve the targets… Then there is the bottleneck of connecting the intelligence to the fire,” and his solution is that “a team consisting of machines and investigators can blast the bottleneck wide open” (Sariel, quoted in Davies). Notably, the first obstacle Sariel identifies is the point at which a human approves a strike to take a life. That a commanding officer’s own doctrinal text frames this deliberative step as a bottleneck to be removed indicates that the brevity of the twenty-second review is not an incidental failure under operational strain, but a designed outcome of the system.

III. Speed Eliminates the Time Judgment Requires and Expands the Killable

RETURN TO THE ISSUE

The Synthetic Battlefield

Volume 2 • Issue 2

Target production now outpaces deliberation, and the institutions responsible have presented this as an achievement. Former Israeli Chief of Staff Aviv Kochavi described the Gospel system in these terms: where the military once generated roughly fifty targets in Gaza over the course of a year, the system produces a hundred in a single day, half of which are then struck (quoted in Davies, McKernan and Sabbagh).

At that pace the requirement that proportionality be weighed case by case becomes impossible, and so proportionality was converted from a judgment into a parameter. Sources described a standing authorization permitting the deaths of as many as fifteen or twenty civilians for every junior operative Lavender marked, and on several occasions more than a hundred civilians in strikes on senior officials (Abraham). For calibration, the American non-combatant casualty value assigned even to Osama bin Laden, a threshold set for a single named individual, was thirty (Gersten, quoted in Abraham), while the strike on the Gaza commander Ayman Nofal was reportedly authorized with roughly three hundred civilian deaths anticipated in advance.

Speed degrades individual decisions, but its effects do not stop there. Shany and Shereshevsky argue that the deeper danger lies in what these systems do to restraint, since international humanitarian law is structured largely around prohibitions and permissions rather than affirmative duties to use force (Shany and Shereshevsky). A combatant may strike a lawful target but is not required to strike every lawful target, and armies refrain constantly.
Decision-support systems dissolve that limit by manufacturing targets faster than humans ever could, compressing the distance between the legal ceiling of permissible conduct and the operational floor at which forces actually operate, and producing lawful destruction on a scale that was previously impossible. Accountability in warfare is conventionally assessed one strike at a time, by asking whether each act broke a rule. But when harm is a property of the pattern rather than the individual act, every strike can be lawful while their accumulation erodes the very restraint the law was meant to secure. A strike-by-strike audit then returns no violation even as the aggregate harm grows.

Beyond the scale of targeting, speed also affected the choice of weapon and the timing of each strike. Because junior targets were plentiful, they were struck only with unguided munitions to conserve more expensive precision weapons (Abraham), and such bombs destroy entire buildings. Where’s Daddy? alerted an officer the moment a marked man arrived at his home, for the straightforward reason, as one officer put it, that a family home is an easier place to strike. The same reporting recounts attacking a house only to find the man was not there, so that a family had been killed for nothing. The machine was better at locating the house than at locating the father.

Fig. 1. A soldier using Project Maven.

The same tempo appears in the American system, where it reflects strategic ambition rather than an accident of war. By March 2026 the Maven Smart System had more than twenty thousand users on a contract ceiling of roughly 1.3 billion dollars, and that month the Pentagon made it a permanent program of record. When Operation Epic Fury began against Iran on February 28, 2026, reporting puts the number of targets struck over three weeks at between 5,500 and 6,000, the first thousand within twenty-four hours. Demonstrating the system publicly, the Pentagon’s Chief Digital and AI Officer, Cameron Stanley, described the identification step as “Left click, right click, left click, magically it becomes a detection,” and called the compression “revolutionary” (quoted in Business Insider). The word doing the work is “magically”: the claim that an object is a particular kind of thing arrives with no account of how, and what has been compressed out is the interval in which a person could have asked why the machine believes what it believes

The failure this paper predicted arrived on the campaign’s opening day, when the Shajareh Tayyebeh girls’ elementary school in Minab was struck, killing at least 175 people, many of them children (Crow). A preliminary Central Command assessment reportedly blamed intelligence maps that failed to show the facility’s conversion from military to civilian use, and 120 members of Congress wrote to the Pentagon asking whether Maven had identified the school as a target and, if so, whether a human verified it. The question has not been answered, and the reason is the argument of this paper: it is not possible to say whether the machine, the data, or the human failed, because the pipeline distributes the failure so evenly that no segment can be isolated and held. Stale maps are precisely the failure SIPRI named as bias in use, and whether this is called a human failure or an AI failure is both accurate and beside the point. The real question is why a system that cannot detect when its own data has gone stale was fielded at a tempo that left no one able to check.

IV. Every Accountability Path Closes on Air

The mechanisms that should assign responsibility all look for the same thing, a decision that can be located, made by an agent who can be named, at a moment that can be dated. Ratification supplies none of the three, which is why every accountability path below fails in the same way.

International courts move in years against systems that move in seconds. In South Africa v. Israel, the genocide case brought before the International Court of Justice, the written pleadings alone now extend to 2029, with South Africa’s reply due in November 2027 and Israel’s rejoinder in May 2029, pushing any judgment on the merits years beyond that (International Court of Justice). The International Criminal Court, having issued arrest warrants for Netanyahu and Gallant in November 2024, then watched enforcement collapse as Hungary announced its withdrawal during a Netanyahu state visit and the United States sanctioned the court’s own prosecutor and several of its judges. No known prosecution anywhere has addressed a harm arising from AI-assisted targeting, and this delay is not incidental to the machinery but functions as its protection.

Self-investigation fails in the same way each time. When Israeli strikes killed seven World Central Kitchen aid workers in April 2024, hitting three vehicles in sequence as survivors fled, the announced consequence was two officers dismissed and three reprimanded, with no prosecution. The base rate makes the pattern clear: of 1,260 complaints of soldier harm to Palestinians tracked between 2017 and 2021, only eleven produced indictments, or 0.87 percent (Yesh Din). The same reflex appeared in response to the Lavender reporting, which the military met by denying that a kill list existed at all, a denial contradicted by six of its own officers. Nor is the failure unique to one military: no one was disciplined for the 2021 Kabul drone strike that killed ten civilians, seven of them children.

Whistleblowing is the one accountability mechanism that works reliably, and it works in reverse. Daniel Hale, who leaked documents showing that in one campaign window nearly ninety percent of those killed by drone strikes were not the intended targets, was sentenced to forty-five months in prison, while no operator or authorizing official has been charged. The same inversion operates on the engineers who build these tools. In 2018 thousands of Google workers forced the company to pledge it would not build AI for weapons, and in February 2025 the company quietly dropped that pledge. The workers who later protested its Israeli cloud contract were fired, more than fifty in a single week, and Microsoft fired engineers who interrupted its anniversary event to say its AI was being used in a genocide. Conscience inside the company turns out to be not a brake on its conduct but a firing offense.

Doctrine is the layer meant to define the human’s role in advance, and it is where the whole accountability structure is supposed to rest. Yet the definition it provides is empty. Department of Defense Directive 3000.09 requires “appropriate levels of human judgment” over the use of force, yet the government’s own analysis concedes there is no fixed level the phrase requires. The directive names the very capacity the system strips away, human judgment, and then declines to say how much of it the law demands. Corporate policy offers even less. Google Photos’ terms prohibit uses causing serious harm, yet no enforcement against the program that misidentified Abu Toha has been reported. And when a company does try to enforce a limit, the system routes around it. Reporting indicated that Anthropic’s Claude models were embedded in Maven, and when the company refused the Pentagon unrestricted access, the Defense Department designated it a supply chain risk and cleared rival models from OpenAI and xAI to take its place, while Claude remained in the Iran operations through a months-long phase-out (CNBC). A policy enforceable only by leaving the supply chain is no constraint on the supply chain.

Fig. 2. The aftermath of an Israeli airstrike in Gaza City on October 9, 2023, leaving widespread destruction in the Rimal area.

International humanitarian law explains why these paths fail in the same way. The obligation that matters here is the duty of precautions, which requires anyone who plans or approves an attack to do everything feasible to verify the target beforehand. Bruun and Bo argue that when a person acts on a faulty recommendation without checking it, the law is broken at the level of precautions rather than distinction (Bruun and Bo 2025). Distinction asks whether the target was lawful, while precautions asks whether the human actually did the work of verifying it, and verification is exactly the step a ratifier skips. The duty does not even require proof of intent, since a negligent failure to take reasonable steps can be enough to constitute a violation, and a targeting method that is unreasonable and produces foreseeable, repeated errors falls outside the bounds of lawful discretion (Bruun and Bo 2025). The errors in Gaza were not surprises, because the system’s error rate was measured before deployment, the bias from Western data was predictable, and the impossibility of real verification in twenty seconds was built into the process.

Yet no one is ever found negligent, for the same reason no one is ever found to have decided. The precautionary duty attaches to a decision-maker, and the ratifier’s gap has already dissolved the decision-maker into a queue of confirmers, each of whom did his twenty seconds correctly, so the law reaches for the negligent human and finds only a signature. Even a located

decision-maker would face no charge, since SIPRI notes the absence of any criminalization of the duty to take precautions in attack (Bo, Bruun and Boulanin 2022). So the obligation these systems most clearly violate is also the only one with no criminal penalty attached, even though it requires no proof of intent and a twenty-second review fails it outright. An officer can fail to verify a target, kill a family, and violate international humanitarian law without committing any offense a criminal court is equipped to try.

Conclusion: What Judgment Would Require

Bias makes the machine look trustworthy, that trustworthiness removes any reason to check, and without checking the judge becomes a ratifier who cannot be held accountable, because no moment of genuine judgment ever took place. Matthias, Sparrow, and Asaro asked who answers when a machine escapes human control. The harder question is now the one in front of us. Who answers when control is fully retained and yet completely empty, when an officer can add 1,200 names to a kill pipeline and recognize it as a decision only afterward?

Any legal response has to be able to tell judging from ratifying, and the distinction has observable correlates that can be stated as conditions, not as new law but as what the evidence suggests would have to be true before a signature could be called a decision. The first condition is time. Was the review interval proportionate to the consequence, or was it a twenty-second quota? Because these systems keep digital logs, the records can answer that question (Bo, Bruun and Boulanin 2022). The second is evidence. Could the reviewer see the underlying intelligence, or only the machine’s score? Detailed information is what closed the gap in Shereshevsky’s experiment, so a reviewer shown nothing but a number is structurally incapable of judgment. The third is dissent. Does this reviewer, or this unit, have any record of overruling the system? A reviewer who has never once rejected an output is a stamp by definition. The fourth is falsifiability. Were there stated conditions under which the human would have said no? A judgment that cannot name what would have changed it was never a judgment at all.

Measured against these conditions, current law falls short. The Secure and Accountable Military AI Act of 2026 establishes that artificial intelligence “supports but does not substitute for human judgment in decisions involving force” and requires “a clearly identified accountable human decision-maker” for each high-consequence system (Secure and Accountable Military AI Act of 2026). Yet naming an accountable human is precisely the move the evidence shows to be insufficient. Without mandated review time, guaranteed access to the underlying intelligence, and any audit of whether the human ever says no, the bill codifies the ratifier and calls him accountable, legislating a person to blame rather than a decision to examine. Whether stronger constraints, such as Shany and Shereshevsky’s proposed presumptions of illegality above fixed harm thresholds (2026), would survive wartime pressure is a question this paper leaves open.

The stakes belong to the people who bore them. Mosab Abu Toha’s two days of interrogation and beating for resembling an entry in a database. The families bombed at five in the morning by a program named for a child’s question. The children killed at a school in Minab on maps no one checked. The more than 72,000 Palestinians killed in a campaign that Amnesty International and a United Nations Commission of Inquiry have concluded amounts to genocide. The machinery that produced those deaths did not escape human control. It kept a human in the loop at every step, gave him twenty seconds and a number, and called his signature a decision. Until the law can name the difference between deciding and ratifying, that signature will keep being enough.

Works Cited

Abraham, Yuval. “‘Lavender’: The AI Machine Directing Israel’s Bombing Spree in Gaza.” +972 Magazine, 3 Apr. 2024, www.972mag.com/lavender-ai-israeli-army-gaza/.

Amnesty International. “You Feel Like You Are Subhuman”: Israel’s Genocide Against Palestinians in Gaza. Amnesty International, 5 Dec. 2024.

Asaro, Peter. “On Banning Autonomous Weapon Systems: Human Rights, Automation, and the Dehumanization of Lethal Decision-Making.” International Review of the Red Cross, vol. 94, no. 886, 2012, pp. 687–709.

Bender, Tyrese. “Artificial Intelligence Bias: Risks for Military Intelligence Operations.” Military Intelligence Professional Bulletin, Jan.–June 2026.

Bo, Marta, et al. Retaining Human Responsibility in the Development and Use of Autonomous Weapon Systems: On Accountability for Violations of International Humanitarian Law Involving AWS. Stockholm International Peace Research Institute, 2022.

Bruun, Laura, and Marta Bo. Bias in Military Artificial Intelligence and Compliance with International Humanitarian Law. Stockholm International Peace Research Institute, 2025, https://doi.org/10.55163/NLWV5347.

“Crow, 120 Members Demand Answers on School Strike in Iran.” Office of Representative Jason Crow, 13 Mar. 2026, https://crow.house.gov/media/press-releases/crow-120-members-demand-answers-on-school-strike-in-iran.

Davies, Harry. “Top Israeli Spy Chief Exposes His True Identity in Online Security Lapse.” The Guardian, 5 Apr. 2024.

Davies, Harry, et al. “‘The Gospel’: How Israel Uses AI to Select Bombing Targets in Gaza.” The Guardian, 1 Dec. 2023.

Frenkel, Sheera. “Israel Deploys Expansive Facial Recognition Program in Gaza.” The New York Times, 27 Mar. 2024.

Human Rights Watch. “Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza.” Human Rights Watch, 10 Sept. 2024, www.hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gaza.

International Court of Justice. Application of the Convention on the Prevention and Punishment of the Crime of Genocide in the Gaza Strip (South Africa v. Israel). Order of 21 May 2026, Fixing of Time-Limits: Reply and Rejoinder.

Matthias, Andreas. “The Responsibility Gap: Ascribing Responsibility for the Actions of Learning Automata.” Ethics and Information Technology, vol. 6, no. 3, 2004, pp. 175–83.

Palestinian Central Bureau of Statistics. Household Survey on Information and Communications Technology. PCBS, 2023.

“The Pentagon Provided a Rare Inside Look at Palantir’s Project Maven and How the AI Tool Helps the Military Wage War.” Business Insider, Mar. 2026, www.businessinsider.com/palantir-project-maven-ai-demonstration-pentagon-2026-3.

Shany, Yuval, and Yahli Shereshevsky. “Military AI and the Specter of the Limitless War.” International Law Studies, vol. 107, no. 1, 2026.

Shereshevsky, Yahli. “The Effect of Military AI on Contemporary Battlefields.” Carnegie Endowment for International Peace, 13 May 2026, carnegieendowment.org/research/2026/05/the-effect-of-military-ai-on-contemporary-battlefields.

Sparrow, Robert. “Killer Robots.” Journal of Applied Philosophy, vol. 24, no. 1, 2007, pp. 62–77.

United Nations Independent International Commission of Inquiry on the Occupied Palestinian Territory. Legal Analysis of the Conduct of Israel in Gaza Pursuant to the Convention on the Prevention and Punishment of the Crime of Genocide. United Nations Human Rights Council, Sept. 2025.

United States, Congress, Senate. Secure and Accountable Military AI Act of 2026. S. 4656, 119th Congress, introduced 2 June 2026.

United States, Department of Defense. Directive 3000.09: Autonomy in Weapon Systems. Department of Defense, 25 Jan. 2023.

Yesh Din. Law Enforcement on IDF Soldiers Suspected of Harming Palestinians: Data for 2017–2021. Yesh Din, 2022.