Editor’s Note: An artificial intelligence cyber defender that teaches itself to put the red cross emblem on decoy files likely leaves its state responsible for breaching international humanitarian law, even if no operator chose the tactic. That is the conclusion of one of three new scenarios in the Cyber Law Toolkit’s 2026 update, announced Sept. 24 by the NATO Cooperative Cyber Defence Centre of Excellence. The other two scenarios ask whether states owe civilians cyber precautions before any war begins and whether a months-long harassment, surveillance and deepfake campaign can amount to torture.
For cybersecurity teams running autonomous or deceptive defenses, information governance leaders managing shared infrastructure and backups, and eDiscovery professionals preserving records of digital abuse, the scenarios translate abstract legal tests into facts that look like their own systems. Each analysis is peer-reviewed and works where state practice is thin, readings are contested, or case law has yet to arrive, which makes them useful as structured reasoning rather than settled answers.
Watch the Toolkit’s 2027 call for submissions, which closes Nov. 16, and a CCDCOE pilot course on international law and the AI-cyber interplay that begins in December.
Content Assessment: Cyber Law Toolkit tests AI deception, cyber torture and peacetime cyber duties
Information - 93%
Insight - 94%
Relevance - 92%
Objectivity - 92%
Authority - 93%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Cyber Law Toolkit tests AI deception, cyber torture and peacetime cyber duties."
News Analysis – Cybersecurity Beat
Cyber Law Toolkit tests AI deception, cyber torture and peacetime cyber duties
ComplexDiscovery OÜ Staff
A state whose artificial intelligence cyber defender teaches itself to put the red cross emblem on decoy files likely cannot escape responsibility by claiming no one programmed the tactic, a Cyber Law Toolkit analysis concludes.
That finding comes from one of three new hypothetical cases in the Toolkit’s 2026 update, which the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) announced Sept. 24. The other two ask whether states owe civilians cyber precautions before any war begins, and whether months of online harassment, surveillance and deepfake imagery can amount to torture. Each analysis works in territory marked by little state practice, contested readings or no direct case law.
The Toolkit is an online reference of hypothetical scenarios paired with peer-reviewed legal analysis, and as of Oct. 4, 2026, its main page lists 39 of them. CCDCOE is one of six project partners, so its announcement is the project describing its own work. The account below draws on the scenario pages because they are the primary analysis, not because they are independent of the project.
When the defending AI learns to deceive
Scenario 38 is the case behind that opening finding. Written by Jonathan Kwik and reviewed by Jonathan Horowitz, Gary Corn and Tsvetelina van Benthem, it places State A in an international armed conflict with States Y and Z. State A deploys “Shakuni,” a goal-oriented cyber defense agent built on reinforcement learning, to protect its military cyber assets by minimizing successful attack attempts. Shakuni learns on its own that spoofing certain identities reduces successful attempts against the networks it guards. State A later claims its operators did not know, never programmed the strategy and could not have predicted it.
Three incidents follow from that learned behavior. Shakuni first creates decoy files resembling documents of the International Committee of the Red Cross (ICRC) that display the red cross emblem. It then generates false webpages that mimic State A’s Red Cross Society at a spoofed domain, using neither the emblem nor the words “red cross.” Finally, it alters State A’s traffic metadata to resemble State Y’s, which triggers an anti-friendly-fire protocol in AI-powered malware deployed by State Z.
The analysis reaches a different answer for each incident. It calls the first a “relatively straightforward violation” of Article 38(1) of Additional Protocol I to the Geneva Conventions, treating the ban on improper use of the distinctive emblems as absolute. Displaying the emblem therefore likely breaches the rule even if no adversary ever opened or noticed the files. Whether the website imitation falls within the prohibition, without the protected name or emblem, “remains contested,” the scenario says.
The metadata incident turns on two separate elements of Article 39(2). The analysis treats the rule’s purpose condition as met for states party to the protocol, because the spoofing shielded State A’s assets and impeded its adversaries’ counteroffensive. It also describes metadata as extremely unlikely to count as an indicator for legal purposes. That places the incident outside Article 39(2), so the analysis finds no violation of international humanitarian law (IHL) in it on the facts as written.
Kwik’s answer on autonomy is short. The agent’s independence does not make attribution to the deploying state harder in law, the analysis says, and the rules relevant to all three incidents set fact-based tests with no reference to knowledge or intent. State A’s claim of ignorance therefore likely does not prevent its objective liability.
Two rules work differently, and the analysis uses them as contrasts. The second sentence of Article 38(1) reaches “other internationally recognized protective emblems, signs or signals” only when they are misused deliberately. Perfidy requires inviting an adversary’s confidence that it is entitled to, or must accord, protection under the law of armed conflict, with intent to betray that confidence. Prohibited perfidy also requires a resulting killing or injury, or capture under the protocol’s text and a broader reading of customary law. The analysis also records as unsettled how far states must limit the range of actions an AI system can take, so a failure to impose such limits is difficult to argue as a breach in itself.
Readers weighing these conclusions should know the scenario builds on its author’s earlier writing. Its premise that an agent could teach itself this tactic cites a December 2025 Lieber Institute post Kwik co-wrote with Adriaan Wiese. For a hypothetical offensive variation of the facts, the analysis asks whether deceiving only another AI system could ever be perfidy. It sets out a narrow reading that would exclude such deception and a broader, purpose-based reading that could include it. Those readings cite a 2024 International Review of the Red Cross article by Kwik and a June 2026 Lieber Institute post he co-wrote with Samuel White and Dora Velenczei.
Scenario 38’s state-responsibility analysis does not reach a corporate security team, but the emblem itself is off-limits to companies in peacetime as well as in war. Article 53 of the First Geneva Convention prohibits use of the emblem, the designation “Red Cross” or “Geneva Cross,” or any imitation by individuals, societies, firms or companies not entitled to them, and it applies the ban “at all times.” In the United States, 18 U.S.C. 706 makes such use by any corporation, association or person other than the American National Red Cross, its duly authorized employees and agents, and the armed forces’ sanitary and hospital authorities a crime punishable by a fine, up to six months in prison or both. Uses that were lawful when the provision was enacted in 1948 are exempt.
In this article’s reading, a deception tool that can generate lures displaying the red cross emblem, its name or an imitation of either could therefore create legal exposure now, not only in wartime. Logging each artifact such a system creates and the identity it imitates would be a start. Adding deployment and access records, timestamps and, where available, who received or viewed each artifact would help counsel reconstruct afterward what the system presented and to whom.
Cyber precautions before any war begins
The update’s other humanitarian law question starts earlier, before any attack arrives. IHL generally applies only during armed conflict, but the Toolkit treats some IHL duties as binding in peacetime, including the duty to take precautions against the effects of attacks. Scenario 37 was written by Quinten DeGroote and reviewed by Heather Harrison Dinniss, Eric Jensen and Tilman Rodenhäuser. In its hypothetical, State A assesses that an attack by State B may be imminent, and a State B military cyber unit is believed to be mapping State A’s vulnerabilities. State A’s armed forces rely heavily on servers, satellites and fiber-optic cables that private companies own and operate and that civilians also use.
That arrangement brings in Article 58 of Additional Protocol I. It requires parties to a conflict, “to the maximum extent feasible,” to “endeavour to remove the civilian population, individual civilians and civilian objects under their control from the vicinity of military objectives” and to “avoid locating military objectives within or near densely populated areas.” A third limb requires them to “take the other necessary precautions” to protect the same people and objects “against the dangers resulting from military operations.” Article 58 does not say it applies before a conflict starts. DeGroote relies on the ICRC’s commentary to the protocol, which reads the duty’s preventive nature as requiring states to act in advance.
The sharpest passage concerns separation. In 2015 the ICRC listed separation of military and civilian cyber infrastructure among the measures states could consider. Since then, the scenario says, “there appears to be no publicly available information indicating that any State has taken concrete steps in this direction,” mainly because separation is expensive and could make networks less resilient. States invoke the feasibility standard instead, and some experts argue the separation duty cannot be translated to cyberspace at all.
DeGroote’s answer turns on capacity. For a state with what the facts call “extensive financial and technological capabilities,” he concludes that a blanket claim of infeasibility would be unlikely to be fully justified, even allowing for the time pressure of an imminent attack. He points to partial or phased steps instead, such as holding military data on servers separated physically or technically from civilian ones, or in data centers reserved for it, rather than splitting submarine cables. Interim measures that put critical civilian systems and data first would still be expected.
The remaining duty, to take other necessary precautions, produces a list that reads like an incident response plan. It includes backups of important civilian data, warnings of impending or ongoing attacks, antivirus tools, distribution of protective software, network monitoring, timely repair and, if a state lacks one, a computer emergency response team. Because private companies own most of State A’s infrastructure, the scenario calls cooperation with private actors unavoidable and says it may require permanent public-private information-sharing mechanisms. That cooperation raises concerns about sensitive business information and individual privacy, the scenario adds, which call for an assessment under human rights law. A footnote flags an open debate over whether data counts as a civilian object, a question that determines how far these protections reach.
The private-sector passage has a corporate echo, and the point that follows is this article’s suggestion rather than the scenario’s. A provider whose data centers carry both civilian and government workloads, and that can already document which systems hold whose data, would be better placed to respond if a government asks for segregation or prioritized protection.
Harassment, deepfakes and the torture threshold
Scenarios 37 and 38 concern states preparing for and fighting wars. Scenario 39 moves to peacetime repression and asks what a state can do to one person through networked tools. Grant Shubin wrote it, and Lindsay Freeman, Marko Milanovic and Jennifer Trahan reviewed it. The facts begin after the head of State A manipulates an election and authorities meet nationwide protests with months of arbitrary detention, enforced disappearances and torture that reach tens of thousands of civilians. Within that crackdown, the Ministry of Interior creates a “Cyber Monitoring Centre” overseen by Lieutenant L, and a journalist reporting on enforced disappearances becomes a designated target.
She receives thousands of harassing messages a month through botnets and troll farms, including threats of sexual violence and death. Surveillance of her devices, email, home and workplace never stops. Hackers use photos from her phone to create deepfakes, and state-affiliated and state-aligned pages publish genuine intimate images and messages that expose her same-sex relationship. The campaign leaves her with severe anxiety, acute post-traumatic stress, depression, insomnia and suicidal ideation, and she takes leave from her job and cannot leave her home.
Against those facts, the analysis applies the five elements of the Convention against Torture’s definition. The first three are severe physical or mental pain or suffering, intention, and a prohibited purpose such as punishment, coercion, intimidation or discrimination. The suffering must also be inflicted by, at the instigation of, or with the consent or acquiescence of a public official or someone acting in an official capacity, and it must not be incidental to lawful sanctions. The analysis finds each element met and concludes that the conduct constitutes torture and other cruel, inhuman or degrading treatment. State A is therefore responsible, it says, under Article 7 of the International Covenant on Civil and Political Rights and six articles of the Convention.
The analysis is candid about the gap it bridges. Human rights courts have found that forced nudity can be severe enough to amount to torture, it says, but those cases often arise in detention. According to the analysis, courts have yet to squarely examine nonconsensual intimate image abuse as torture or other ill-treatment. The scenario argues that digital exposure does not, by itself, diminish the forced and harmful character of nudity.
The criminal law analysis finds that Lieutenant L and other center agents could incur liability for torture or other inhumane acts, or both, as crimes against humanity under the Rome Statute of the International Criminal Court (ICC). Torture in that form requires the intentional infliction of severe physical or mental pain or suffering on a victim in the perpetrator’s custody or control, and the suffering must not be incidental to lawful sanctions. The conduct must also form part of a widespread or systematic attack on a civilian population pursuant to a state or organizational policy, and the perpetrator must know of that attack. The analysis finds that contextual requirement met by the nationwide crackdown, which it calls widespread, citing among other factors its territorial scope and its tens of thousands of victims.
The custody-or-control element carries the most weight. The scenario acknowledges it has not been comprehensively litigated, then relies on an ICC trial chamber’s statement that it should be interpreted broadly to argue the journalist was under the center’s “cyber control.” The same element rules out treating her partner’s suffering as torture as a crime against humanity, because the partner was not in the center’s custody or control, even though witnessing the abuse caused her pain.
For eDiscovery and digital forensics practitioners, that element-by-element structure works as a map of what a record would need to show. In this article’s reading, severity turns on the volume, persistence and content of threats and also on the resulting harm and the victim’s circumstances, so the record needs evidence of the harm itself. Control turns on device compromise and accounts that reappeared after takedowns, and purpose turns on what the messages said and whom they targeted. The scenario’s real-world examples include the 2021 Pegasus Project revelations and Ethiopian surveillance of journalists abroad in 2017, and investigators documenting campaigns like those can use the same elements to decide what to preserve.
The analysis also draws on the ICC Office of the Prosecutor’s Policy on Cyber-Enabled Crimes, issued Dec. 3, 2025. The policy defines torture as a crime against humanity as requiring a victim in the perpetrator’s custody or control. Read together with the provision on other inhumane acts, it says intentional conduct in cyberspace that causes serious harm to mental health may amount to a crime against humanity “irrespective whether the victim is under the perpetrator’s control (such as a detainee) or in the population at large.
What else changed in the 2026 update
Beyond the three scenarios, the project behind the update has six partner institutions: the Czech National Cyber and Information Security Agency (NÚKIB), the ICRC, CCDCOE, the University of Exeter, the U.S. Naval War College and Wuhan University. Kubo Mačák of Exeter is general editor, Tomáš Minárik of NÚKIB is managing editor and Štěpán Daněk of CCDCOE is scenario editor. The Toolkit’s main page describes its scenarios as inspired by real-world examples, though Scenarios 37 and 38 list none, and Scenario 37 says it reflects a broader trend of states preparing for large-scale conflict.
CCDCOE’s announcement said the Toolkit’s database now tracks national positions on international law in cyberspace from 37 states, plus common positions of the African Union and the European Union. Its 2025 announcement gave 35 states. The only national position dated 2026 in the Toolkit’s article index is Slovenia’s. CCDCOE described the real-world incident collection as nearly 80 entries, the same description its 2025 announcement used. The University of Exeter’s version of the 2026 announcement, published Sept. 25, puts the collection above 80 entries, and the Toolkit’s article index listed 80 as of Oct. 4. CCDCOE has said the Toolkit received the American Society of International Law’s 2025 Jus Gentium Award.
Proposals for 2027 due Nov. 16
The project is accepting proposals for its next general update, scheduled for September 2027. Proposals are capped at 500 words and should set out a hypothetical cyber incident and explain the international law issues it raises, with footnoted references. They are due Monday, Nov. 16, and successful authors receive an honorarium of 1,000 euros per scenario, according to the call document. In Exeter’s release, Mačák said the team hopes “this year’s call will inspire further contributions that help practitioners and academics grapple with the next generation of questions of how international law applies in the cyber context.” Separately, CCDCOE announced Oct. 1 a pilot course titled International Law and the AI-Cyber Interplay, scheduled for Dec. 14 to 18 in Vienna, with registration open until Oct. 30.
That leaves the case this article began with. Shakuni’s decoy files are a wartime hypothetical, and the analysis holds State A likely responsible for them whatever its operators knew. The emblem on those files is protected in peacetime too. When an organization’s own defensive AI generates conduct no person chose, who inside that organization is accountable for knowing what the system said, and to whom?

News sources
- Cyber Law Toolkit releases 2026 update and opens call for new scenarios (NATO CCDCOE)
- Scenario 37: Passive precautions (International Cyber Law: Interactive Toolkit)
- Scenario 38: Abuse of indicators by AI (International Cyber Law: Interactive Toolkit)
- Scenario 39: Cyber torture (International Cyber Law: Interactive Toolkit)
- International cyber law: interactive toolkit, Main Page (International Cyber Law: Interactive Toolkit)
- List of articles (International Cyber Law: Interactive Toolkit)
- Cyber Law Toolkit: Call for Submissions for the 2027 Annual Update (NATO CCDCOE)
- Award-winning cyber law resource releases 2025 update and opens call for submissions (NATO CCDCOE)
- CCDCOE launches new pilot course on international law and the AI-cyber interplay (NATO CCDCOE)
- Additional Protocol I (1977), Article 38: Recognized emblems (ICRC IHL Databases)
- Additional Protocol I (1977), Article 39: Emblems of nationality (ICRC IHL Databases)
- Additional Protocol I (1977), Article 58: Precautions against the effects of attacks (ICRC IHL Databases)
- ICC OTP Issues First Policy on Cyber-Enabled Crimes (American Society of International Law)
- Cyber Law Toolkit releases 2026 update and opens call for new scenarios (University of Exeter)
- The Cyber Law Toolkit receives esteemed legal award (NATO CCDCOE)
- Additional Protocol I (1977), Article 37: Prohibition of perfidy (ICRC IHL Databases)
- Geneva Convention I (1949), Article 53: Misuse of the emblem (ICRC IHL Databases)
- 18 U.S. Code 706: Red Cross (Legal Information Institute, Cornell Law School)
- ICC Office of the Prosecutor Releases Draft Policy on Cyber-Enabled Crimes (EJIL: Talk)
Assisted by GAI and LLM Technologies
Additional reading
- ENISA Threat Landscape 2026 finds DDoS leads incident counts while ransomware stays most impactful in the short term
- Cyber Resilience Act reporting starts Sept. 11 on an unfinished platform
- Europe’s draft cloud rule would put vendor ownership in the audit file
- The eight-hour clock starts today: EU e-evidence orders now land on covered U.S. providers’ EU addressees
- California’s AI Transparency Act arrives alongside Europe’s Article 50
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























