Authored by Nikitha K., a 1st-Year LLM (Investment and Securities Law) student at Maharashtra National Law University and National Institute of Securities Markets
Introduction
Instead of tanks, the first mobilisation that Russia saw in Ukraine in February 2022 was teens with laptops in their hands. In days[nk1] [nk2] [nk3] the number of the “IT Army” of volunteers in Kyiv was already hundreds of thousands, and the international lawyers, who were left to contemplate the situation, started to find themselves in a situation which the Geneva Conventions could never have imagined. There is a common understanding shared even by the International Committee of the Red Cross (ICRC) that international humanitarian law (IHL) already applies to cyber warfare, as it does to any other type of warfare. You are correct if you said that answer. It’s also, this piece says, pretty irrelevant. The real problem is not whether IHL does apply to cyberspace; it does, but that the underpinning structure that lays the groundwork for IHL – uniformed armies and physical fronts – is incapable of creating a coherent framework in which to classify today’s decentralised digital combatants. The result is a legalised and virtually empty system.
The Settled Question, and Why It Distracts
Thus, for more than ten years, the debate over applicability has been a feature of cyber-law scholarship, and has even been a feature of the ICRC’s own position papers, from the initial project on the Tallinn Manual onwards. All credible authorities now hold that these rules of distinction, proportionality, necessity and precaution also apply in cyberspace just as they do in other theatres of war, be that the land, sea or air. But this consensus is a sort of law blanket. It allows institutions to claim success on the rhetorical question, but the real question, one that counts when actions taken by anonymous, decentralised, fighting groups are legal ones to be taken against, is hardly answered. It seems that a rulebook that cannot classify players on the field is worthless. But the humanitarian stakes are with that classification, not with the applicability debate.
Keystroke: The Vanishing Line – Civilians as Combatants
A Civilian Status of which one can switch off.
The IHL’s entire protective structure rests on a single dichotomy: combatants may fight and be fought, while civilians may not fight and may not be fought, unless they take direct part in the hostilities (DPH). In the midst of cyber conflict, it’s being eaten away from the inside. The decentralised structure of Ukraine’s IT Army and the fact that its members are organised on Telegram, as opposed to having a command hierarchy that IHL demands of a fighting force, mean that they are not a formal armed group but still civilians, as the Lieber Institute has noted. However, civilian status is not a “privilege”; it is a “privilege that is subject to and may be revoked.”
The Three-Part Test in Practice.
As the EJIL: Talk! analysis of the IT Army will explain, under ICRC’s ‘three-part test’ threshold of harm, direct causation and belligerent nexus, a volunteer who disables a website belonging to the Ministry of Defence is likely to be protected, whilst one who disrupts a railway network carrying Russian troops has probably violated the direct participation test and forfeited that protection. The problem is this lawful test is not being performed by any hacktivist logging in to a common dashboard for the botnet before clicking submit.
An inquiry that no Volunteer can run.
But, as the ICRC has pointed out, “no one that participates in war is beyond these rules”, but a volunteer-based crowd is structurally unable to perform the inquiry required by the rules act-by-act and case-by-case. The result is that those whom IHL is meant to protect are being pushed, unwittingly, by their own governments’ recruitment programs, in and out of legitimate target status.
Attribution as Alibi
Effective Control meets No Control
This classification gap is not as bothersome as it would be if it were just definitional. It is not, as it is directly linked to the second failure, that of state responsibility. IHL only attaches itself to states by attaching to them; and cyberspace was designed for the express purpose of defeating IHL. The traditional “effective control” test fails on the scenario in which the “militia” is a self-organising group of people in an online environment. Further, the government provides tacit approval, funding or distant praise.
In the absence of answers, what options can be considered?
As autonomous, machine-learning-enabled cyber tools exacerbate the issue, commentary on the new revision of the Tallinn Manual points to the fact that as an AI-directed attack goes beyond its human hands-on operator. The settled doctrine of attribution has no definitive answer as to whose actions are being measured. This is NOT an academic deficit. The structural dynamics that incentivise outsourcing digital warfare to volunteers who can plausibly deny responsibility to the law is just as true for the case of Telegram channels, as it is for the case of tank columns. The lines between attribution of responsibility get more permeable every day. However, IHL’s guarantee of accountability becomes more of an “alibi” for the state’s actions.
What Tallinn 3.0 Must Fix
Borrowed Categories, ill-Fitting Rules
Most commentators, even the ICRC in its famous rules for civilian hackers, have been tempted to take with them ideas from the “heroic age” of kinetic war. The function of continuous combat, levée en masse, direct participation, wholesale, etc., apply them to cyberspace. In this article, it’s asserted that instinct itself is a part of the problem. Such categories were created with reference to the visible, physical and mostly irreversible acts of violence; cyber operations are invisible, reversible and performed at a scale. The anonymity was unimaginable at the time the 1977 Additional Protocols were drafted. The decision to remove someone of their status as a civilian should not be made lightly, as “simply downloading an app to help with a DDoS campaign is not enough” to remove someone of their civilian status, experts tell Swissinfo.
A new Functional Class for Digital Participation
The warning is appropriate, but not mandatory. In the upcoming Tallinn Manual 3.0 project, they are not going to be able to tweak the existing tests on the edges of the current law in any way. It should instead establish a truly new functional class of digital participation that is based on the technical severity of the act. However, there’s no potential for irreversible protection loss, forcing all of these keystrokes into a combatant/civilian binary created for riflemen.
The message is: I would like to shift the Burden Back to States.
Combine with rebuttable state responsibility for cyber operations from government-run infrastructure. It is explicitly authorised by government officials, which currently affords states protection by their volunteer proxy. Every future mobilisation like Fedorov will work out similarly; civilians are legally and, in some ways, ambiguously defined. The state is not accountable. The legal system is the one that is patting itself on the back for having defined what offence it can see and what is not.
Conclusion
IHL is not the right forum to have another piece of paper stating that it applies to cyber warfare. It must have the intellectual guile to acknowledge that its traditional battle-dress and trench-dress culture is under stress from a war conducted by volunteer troops from behind a computer screen. There is a real chance in the next edition of the Tallinn Manual to not only redefine the rules for a new domain, but to create categories that the domain deserves. So long as it remains a battlefield, a law will have jurisdiction over it that it can never enforce, and it will never be able to assure protection for it.


