On October 1, 2026, the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn announced a pilot course, International Law and the AI-Cyber Interplay. It will run December 14-18, 2026 in Vienna. It is aimed at state and military legal advisers who already know international cyber law, and registration closes October 30. The Centre calls it "the natural continuation" of its International Law of Cyber Operations Course and says it intends to make the course an annual offering. The announcement credits support from NATO's Science for Peace and Security Programme.
This is a training announcement, not a regulation. It still shows how Estonia's flagship defence institution is choosing to handle AI in military cyber operations, and that choice is sensible.
The case for a new rulebook
The strongest argument for new binding rules goes like this. AI-enabled cyber tools can act at machine speed, may select targets without a human in the loop, and can be hard to attribute. Law written for human decision cycles may not map onto that. A week before the course announcement, on September 24, the CCDCOE-backed Cyber Law Toolkit released its 2026 update. One of its three new scenarios, Scenario 38, examines the "abuse of protected indicators by an AI cyber defence agent during an international armed conflict." That means an automated defender that spoofs or misuses a protected emblem. A critic could fairly say that if the field's own reference work needs hypothetical cases this exotic, the existing framework is being stretched.
Why training beats treaty-drafting right now
The stretch is real, but it is a reason to train people, not to legislate early. Three points support that.
First, the CCDCOE's own scholars reject the premise that AI makes current law obsolete. In a July 2026 Opinio Juris symposium introduction, Centre-affiliated editors Nick Wobma, Maria Tolppa and Kubo Mačák argue that existing rules should be "interpreted and applied in ways that preserve their effectiveness." The symposium's themes are practical: governance across an AI system's lifecycle, legal reviews as a continuing process rather than a one-time sign-off, and machine-to-machine deception. None of that needs new treaty text. It needs advisers who can apply the law to specific systems.
Second, states are unlikely to agree on detailed new rules soon. Jeffrey Biller, writing for West Point's Lieber Institute in "Year Ahead 2026", describes "formal stability in the law alongside growing practical indeterminacy in its application." In his account, states reaffirm that international humanitarian law applies to cyber operations but avoid spelling out how distinction and proportionality work, because vagueness preserves operational flexibility. Biller also warns that approving each operational use of a system individually is "poorly suited to high-tempo cyber operations conducted through AI-enabled systems." He expects legal review to shift toward governance built into system design, training and testing.
That last point explains the course. If review moves earlier, into procurement and design, the lawyers doing it need to be literate in both the law and the technology. A legal adviser who can only answer questions after an operation is under way is of little use when the decisions are made in the architecture. A pilot course for advisers who already know the basics is a direct, low-cost response.
Why this fits a pro-innovation view
Proportionate regulation does not mean no rules. It means rules that match the evidence and don't lock in guesses. Binding AI-specific cyber-warfare treaties negotiated today would be written before anyone knows how autonomous cyber agents behave in practice. They would also be written by governments that, on Biller's account, prefer ambiguity. The likely result is either lowest-common-denominator text or provisions that technology overtakes within a few years.
Building a pool of competent advisers has no such drawback. It improves how existing law is applied inside militaries, and it does not restrict the civilian AI and security industry. The same goes for the Toolkit. It is a scenario-based reference, not a legislative proposal, and it works by showing how the law applies to concrete facts. Its 2026 update adds three scenarios. It also now holds nearly 80 real-world incidents and tracks the positions of 37 states plus the African Union and the European Union. That is a reasonable evidence base for deciding later whether any gap actually needs filling.
The Centre's other long-running project points the same way. The Tallinn Manual 3.0 project, which the Centre describes on its research pages, began in 2021 as a five-year revision of the existing manual. It is a non-binding scholarly work. Estonia's institutional approach has been consistent: write down how current law applies, publish it, and train practitioners. It has not pushed for a new convention.
What to watch
The approach has limits, and a fair assessment should say so. A course for state and military lawyers does nothing for the civilian side. Biller's concern is that states will keep their interpretations private, and training advisers does not make those interpretations public. If legal clarity ends up inside classified review processes, outside observers, including companies whose infrastructure sits in the line of fire, will still lack clear expectations. The Toolkit's open call for submissions (deadline November 16, 2026, with paid contributors) is a partial remedy because it invites outside authors to shape the scenarios.
Three markers will show whether the pilot matters:
- Whether it becomes annual. The Centre says it intends this, and repeat runs would signal real demand from ministries and defence staffs.
- Whether participating states publish positions. The Toolkit already tracks 37 national positions, so any growth in that count is measurable.
- Whether Scenario 38-style questions reach official doctrine. If the exotic case becomes a routine review item, the training will have worked.
The lesson for tech policy generally is that the first response to a new technology should often be capacity, not statute. Tallinn is betting that well-trained lawyers applying existing law will serve better than a hurried new rulebook. On the evidence available today, that bet is sound.