An autonomous weapon does not possess legal authority. Commanders and operators do. But every autonomous weapon still has an engineering permission state: the set of actions its software is allowed to execute without fresh human input.
On an electronic-warfare battlefield, that permission state can become a target.
Consider a loitering munition operating inside a commander-approved engagement envelope. Its datalink drops. Satellite navigation becomes unreliable. Smoke, decoys, or electronic attack degrade the sensor picture. The system correctly contracts its permissions and stops short of its widest engagement mode.
Then one thing gets better:
A clean position update arrives. A target track stabilizes for a few seconds. The link flickers back. If the software treats recovery as the mirror image of failure, full permission can snap back as soon as one threshold crosses from red to green.
That is not merely a sensor problem. It is a recovery problem. And in a contested electromagnetic environment, recovery itself can be manipulated.
The Army and the joint force are already moving in the right direction on the larger problem. A 2025 Modern War Institute article argued that unmanned systems will need versions of commander’s intent to continue useful missions when communications are severed. More recent MWI-published analysis of the autonomous battlefield likewise calls for machines to receive encoded boundaries, target-recognition constraints, abort rules, and conditions for continuing, rerouting, waiting, or engaging under degraded navigation and connectivity.
The unresolved question is narrower: Once a system has correctly lost a higher permission because the evidence supporting it degraded, what evidence must it accumulate before that permission returns?
The answer should be asymmetric: Contract immediately, but recover deliberately.
That principle is already compatible with Department of Defense policy. DoD Directive 3000.09 requires autonomous and semiautonomous weapon systems to allow commanders and operators to exercise “appropriate levels of human judgment over the use of force.” It requires verification, validation, and testing against adaptive adversaries using realistic countermeasures. And when a system cannot complete an engagement within the relevant time, geographic, environmental, and operational constraints, the directive says it should terminate the engagement or obtain additional operator input before continuing.
The directive also requires legal reviews of intended acquisition, procurement, or modification for consistency with domestic and international law, particularly the law of war. That matters here because the proposal is not to give software legal command authority. It is to make the engineering conditions under which software may execute preapproved engagement logic explicit, testable, and reviewable before employment.
DoD’s newer test-and-evaluation procedures make the opening even clearer. DoD Manual 5000.101 directs operational and live-fire testing of AI-enabled and autonomous systems to include cognitive electronic attack, adversarial inputs, safety and security under operationally relevant conditions, and the expanded attack surface created by data, models, and sensing. It also calls for exploration of failure states and degraded states across the system life cycle.
In other words, DoD already requires the pieces. What is not yet made explicit as a standard test observable is the permission state over time.
Army professional debate is moving toward the same seam. A recent Military Review essay on integrating lethal autonomous weapon systems into targeting argues that commanders should encode target-selection standards and attack guidance into engagement logic, continuously supervise system performance, and withdraw delegated execution authority when reliability degrades or conditions change.
But revocation is only half the problem. Restoration needs a rule too.
Without one, the system can enter permission flapping: repeated movement between higher and lower action states as its evidence hovers around a threshold. Engineers already use hysteresis to prevent physical systems from chattering around unstable boundaries. Autonomous weapons need the operational equivalent. A failed mandatory condition should contract the permission envelope immediately. Re-expansion should require persistent valid evidence, independent corroboration, fresh operator input, or some combination appropriate to the mission.
The exact recovery rule should not be universal. That is where the Army’s variation across formations, missions, weapons, and operational conditions matters. A short-range defensive system facing saturation attack will need a different recovery contract than a loitering munition operating near civilians, a counterdrone interceptor, or an autonomous reconnaissance platform cueing indirect fires. The requirement should therefore specify the process, not dictate one number.
That process can be written in four parts.
First, define the evidence envelope for every action class. What must currently be true for the system to navigate, transmit, nominate a target, track it, recommend an engagement, or execute one? The answer may include sensor health, target identity, navigation integrity, freshness, consistency across modalities, geofences, protected-site constraints, and operator status. The legal and operational review should see those dependencies before fielding, not discover them after an incident.
Second, distinguish contraction from recovery. Mandatory failures should take effect immediately. Recovery should require evidence that persists long enough to show that the system has actually returned to a valid operating condition. One clean frame should not automatically erase thirty seconds of corrupted evidence.
Third, bind the recovered permission to the evidence that earned it. If the sensor frame, model version, navigation solution, target track, or policy state changes before execution, the previous authorization token should not float forward as if nothing changed. The executor should be able to answer a simple question: Is this action still tied to the evidence state that justified it?
Fourth, make the recovery gate a red-team target. Testers should not only ask whether jamming, spoofing, decoys, or sensor degradation fool the classifier. They should plot the permission envelope during the attack. Does authority contract at the declared point? Does it recover too early? Can pulsed interference make the system oscillate between engage and do-not-engage states? Can stale evidence survive across a version change? Can a temporary clean interval restore permissions that the broader evidence no longer supports?
This is where the legal, doctrinal, and test layers meet. The law-of-war review does not need to occur at machine speed. It needs to examine, before employment, the engagement logic and the transition conditions that will operate at machine speed. Commanders do not need to micromanage every sensor threshold. They need confidence that the system cannot quietly reacquire a class of action after the factual premises for that permission have changed.
There is an obvious objection. If an adversary knows that degraded observability narrows a weapon’s permissions, it will jam continuously and create sanctuary. But that is not an argument for leaving permissions unchanged. The adversary is already attacking sensing, timing, navigation, and communications. Full authority under degraded evidence does not defeat electronic attack. It simply converts uncertainty into permission.
The better response is to design a useful degraded-mode floor before the mission. A weapon may lose permission to engage while retaining permission to navigate, sense, preserve a track, reposition, relay data, or return to a designated area. Some target classes may remain eligible under multiple independent onboard modalities while others require fresh external confirmation. The system should lose only the permissions whose evidentiary premises have failed.
This also denies the adversary a subtler opportunity. Intermittent interference can be cheaper and harder to locate than continuous jamming. If full permission returns after a single favorable sample, the enemy gains a new control surface: It can shape when the machine is permitted to act by manipulating evidence around the recovery boundary.
That is why the recovery gate belongs in requirements, legal review, test planning, and tactics. Not because every unit or every autonomous system faces the same problem in the same way, but because every system that can lose and regain permission needs a declared answer to the same question: What must be true before it gets that permission back?
The joint force is correctly building autonomous systems that can continue to function when communications and navigation degrade. The next step is to make sure resilience does not become automatic reauthorization.
A weapon that can fight through jamming is resilient. A weapon that knows the first clean sample is not permission to shoot is governable.
Burak Oktenli is an independent researcher based in Washington, DC. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and an MBA, and is completing a master of professional studies in applied intelligence at Georgetown University. His research focuses on assurance, autonomous systems, physical AI, and runtime authority.
The views expressed are those of the author and do not reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Image credit: Spc. Julian A. Winston, US Army

