The Alliance Has No Common Answer To A Machine-Speed Question

Abstract: NATO has spent three years building the technical scaffolding to field autonomous systems across its member states, and has largely succeeded at interoperability, defined as an engineering property: allied machines can operate as one. It has not resolved a harder property of authority. When an autonomous system proposes a lethal action faster than a human can meaningfully review it, and two allies operating the same kill chain hold different national thresholds for permitting that action, whose threshold governs, and who is accountable when they disagree?

Problem statement: When two NATO allies operate the same autonomous kill chain at machine speed but hold different national thresholds for permitting a lethal action, whose threshold governs, and who is accountable when they disagree?

So what?: Before fielding a shared autonomous capability, each participating state should declare its authority threshold in machine-readable form; the shared system should default to the most restrictive declared threshold, log which threshold it applied at the moment of action, and rehearse threshold disagreement in coalition exercises.

Source: shutterstock.com/Shutterstock AI
Source: shutterstock.com/Shutterstock AI

The Gap Interoperability Left Behind

Public worry about artificial intelligence and nuclear weapons runs along a familiar axis: the United States, Russia, and the People’s Republic of China (PRC), each tempted to wire faster machine reasoning into nuclear warning and retaliation. The 2026 Doomsday Clock statement, which set the clock at eighty-five seconds to midnight, calls on the three powers to agree on guidelines for AI in their militaries.[1] That worry is correct, but it misses a quieter, closer problem: the alliance on the same side of it.

NATO has spent three years building the scaffolding to field autonomous systems across its member states: an Autonomy Implementation Plan, six Principles of Responsible Use for AI in defence, and a steady cadence of interoperability exercises designed to enable allied systems-of-systems to operate together.[2] What it does not have, and what no alliance has, is a common answer to a simple question: when an autonomous system proposes a lethal action faster than a human can meaningfully review it, whose threshold governs, and who is accountable when thresholds disagree? This is not hypothetical: the gap opens the moment two allies with different national rules operate the same kill chain.

Consider a modern strike. In the 2020 Nagorno-Karabakh war and since, the sequence from detection to destruction has been distributed across systems exercising distinct levels of autonomy: a loitering munition that selects and strikes on its own; a human-confirmed follow-up; a decoy flown to draw the air defences that another autonomous system then destroys.[3] Each link sits at a different point between full human control and full autonomy, and the chain works because the timing is compressed, faster than a deliberate human decision cycle.

Now place that chain inside a coalition. One ally’s doctrine requires a human to authorise each engagement; another permits autonomous engagement within a pre-approved box; a third treats the same action as routine self-defence needing no specific authorisation. On a shared network fielding interoperable systems, exactly what NATO’s plan is designed to achieve, these rule sets do not resolve into one; they collide. The system does not pause at the national boundary to ask which standard applies; it acts at the speed it was built for, and the authority under which it acted becomes a question answered only afterwards. The divergence among allies is documented rather than hypothetical: Germany’s 2021 coalition agreement rejects lethal autonomous weapon systems that operate entirely without human control and commits to pressing for their international proscription, while United States policy under Department of Defence Directive 3000.09 permits such systems subject to “appropriate levels of human judgment”, a standard official United States guidance describes as deliberately flexible. The allies do not even share a vocabulary: NATO expert bodies have worked in terms of “meaningful human control”, a phrase the United States rejects.[5]

Machines rather than Authority

The alliance’s response so far has been to standardise the machines, not the authority. NATO’s Principles of Responsible Use- lawfulness, accountability, governability, traceability- are real and serious, but they are principles, not thresholds. They tell a member state that its systems must be accountable and governable; they do not tell two members whose thresholds differ which prevails when their systems act together in the same second. Interoperability has been defined as a property of equipment: the ability of systems to exchange data and operate as a single system. The harder property is one of authority: whether these states’ rules for using force can be exercised as one, at machine speed, and without a gap into which accountability disappears.[6] Concretely, the ambiguity lies between three candidates: the state whose platform executed the strike, the state whose sensors and data cued it, and the commander whose network configuration fixed the engagement threshold. Each is a plausible locus of command responsibility, and none is designated in advance.

That gap is structurally different from the rival-facing risk that dominates the conversation. Between adversaries, the danger is escalation through misperception, one side’s automated response read as an attack. Within an alliance, escalation occurs through diffusion: an action taken at one member’s permissive threshold, on a shared system, that commits the whole coalition to consequences that its more cautious members never authorised. The cautious ally discovers, after the fact, that it was party to a strike its own rules would have forbidden, because the system was interoperable and authority was not. This is not yet a live crisis. However, the direction of current development, toward faster autonomy on shared networks, makes it an increasingly foreseeable one.

One might assume the chain of command resolves this: a coalition has a commander who decides. However, machine-speed autonomy is precisely the condition under which the commander’s deliberate decision has been compressed out. Distributing a kill chain across autonomous links is meant to run faster than the cycle a commander would impose, so invoking the commander describes the slow system autonomy was built to replace. NATO’s own joint targeting doctrine illustrates the point. The allied targeting cycle is a deliberate, phased process built around commander decision points, precisely the tempo that autonomous engagement is designed to outrun.[7]

None of this argues against allied autonomy or cooperation. It argues that the alliance has solved the easier half of its problem and called it the whole. Making the machines talk to one another is the engineering achievement; agreeing on whose authority governs when they act, and ensuring every action leaves a record of which threshold permitted it, is the governance achievement, and it has barely begun.

Three Commitments

Three commitments, none requiring new institutions, would close most of the gap. First, treat authority as a graded, declared property of every shared system: before fielding an interoperable capability, each state should declare, in machine-readable form, the threshold at which its rules permit autonomous lethal action, and the shared system should default to the most restrictive declared threshold. An alliance is only as permissive as its most cautious member consents to be, and the system should enforce that automatically rather than discover it in an inquiry. Second, make every engagement leave an authority record: a system can log, at the moment of action, which threshold it applied and under whose authority it did so. The technology exists; the requirement to use it does not. Third, treat threshold disagreement as a planning input rather than an operational surprise. Coalition exercises already rehearse whether allied systems interoperate; they should also rehearse what happens when allied authorities do not align. The natural owner of all three commitments is NATO itself: the standardisation machinery that already certifies technical interoperability can be extended to certify authority interoperability, making a declared threshold, an authority record, and a rehearsed disagreement procedure as much a condition of fielding on allied networks as a common data format is today. That step would carry the alliance’s interoperability agenda beyond equipment and into the authority under which it operates.

A comfortable assumption in Western strategic circles holds that because human beings design these systems, human beings will remain able to govern them. The alliance gap is a clean test of that proposition. It is not a problem of malicious code or rival sabotage, but of member states that have agreed on the machinery of autonomous warfare without agreeing on who, in the coalition, is permitted to decide, and how quickly. The rivals across the table are worth worrying about. But an alliance that can make its autonomous systems act as one, without agreeing on whose finger is on the trigger or how fast it may move, has built a machine-speed question it has not given itself a way to answer. The time to answer it is before the system does.


[1] Science and Security Board, “2026 Doomsday Clock Statement,” Bulletin of the Atomic Scientists, January 27, 2026, https://thebulletin.org/doomsday-clock/2026-statement/.

[2] North Atlantic Treaty Organization, “Summary of NATO’s Autonomy Implementation Plan,” October 2024, https://www.nato.int/cps/en/natohq/official_texts_208376.htm; North Atlantic Treaty Organization, Principles of Responsible Use of Artificial Intelligence in Defence (2021; rev. 2024).

[3] Shaan Shaikh and Wes Rumbaugh, “The Air and Missile War in Nagorno-Karabakh: Lessons for the Future of Strike and Defense,” Center for Strategic and International Studies, December 8, 2020, https://www.csis.org/analysis/air-and-missile-war-nagorno-karabakh-lessons-future-strike-and-defense.

[4] Vincent Boulanin, Neil Davison, Netta Goussac, and Moa Peldan Carlsson, Limits on Autonomy in Weapon Systems: Identifying Practical Elements of Human Control (Stockholm and Geneva: Stockholm International Peace Research Institute and International Committee of the Red Cross, June 2020), https://www.sipri.org/publications/2020/policy-reports/limits-autonomy-weapon-systems.

[5] Sozialdemokratische Partei Deutschlands, Bündnis 90/Die Grünen, and Freie Demokraten, Mehr Fortschritt wagen (coalition agreement, Berlin, November 2021); U.S. Department of Defense, Directive 3000.09: Autonomy in Weapon Systems, January 25, 2023, https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodd/300009p.pdf; Congressional Research Service, “U.S. Policy on Lethal Autonomous Weapon Systems,” In Focus IF11150; and Stiftung Wissenschaft und Politik, “Autonomous Weapons Systems: UN Expert Talks Facing Failure,” SWP Comment 2022/C43, https://doi.org/10.18449/2022C43.

[6] North Atlantic Treaty Organization, AJP-3.9, Allied Joint Doctrine for Joint Targeting, ed. B (Brussels: NATO Standardization Office, 2021).

[7] North Atlantic Treaty Organization, AJP-3.9, Allied Joint Doctrine for Joint Targeting, ed. B (Brussels: NATO Standardization Office, 2021).

Categories

Institutions gain IP-authenticated and remote digital access to all issues of The Defence Horizon Journal’s Special Edition.

Digital access is: 

  • Fully-searchable;
  • With intuitive display options;
  • Accessible and VPAT-compliant (including read-aloud technology); 
  • Cross-platform compatible;
  • Includes usage reports and MARC records.

Institutions can access a free 1-month trial and/or request pricing.

Languages

Sign Up For Our Newsletter

Get the content you need, just when you need it.

DONATE

Support our mission by making a donation.

Visit our Partner