The NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), headquartered in Tallinn, has spent July 2026 laying out its most detailed case yet for rethinking how international law governs military artificial intelligence. Through an ongoing Opinio Juris symposium and a forthcoming Oxford University Press volume, International Law and Artificial Intelligence in Armed Conflict: The AI-Cyber Interplay, CCDCOE-linked scholars are pressing a specific and consequential claim: legal oversight of military AI-cyber systems cannot be confined to the moment a weapon is used. It has to run across the system's entire lifecycle — design, development, testing, procurement and deployment (Opinio Juris, 20 July 2026).
The Argument for Lifecycle Review
The strongest version of this case comes from Marco Roscini, a University of Westminster professor and CCDCOE senior fellow, writing in the symposium. He argues that Common Article 1 of the Geneva Conventions — the obligation to "respect and ensure respect" for international humanitarian law — is under-exploited as a governance tool. States, he writes, "are expected to take all reasonable measures to prevent foreseeable violations and minimise the risks associated with military uses of AI," and that duty attaches to "choices made throughout the entire lifecycle of AI systems," not merely to the commander's decision to fire (Opinio Juris, 20 July 2026).
This is not an abstract point. Roscini pairs it with a practical critique of Article 36 weapons-review practice — the standard IHL mechanism requiring states to assess new weapons for legality before fielding them. "Legal review cannot be regarded as a one-off exercise," he writes. "Unlike many conventional weapons, AI systems may evolve through software updates, retraining or changes in the operational environment." A missile's targeting logic doesn't usually rewrite itself after deployment; a machine-learning model can. Fellow contributors Netta Goussac and Rain Liivoja make the same point from a different angle, arguing legal review should function as "an ongoing governance mechanism" rather than a static compliance checkbox.
The argument has institutional weight behind it. CCDCOE, established by Estonia and six allied nations on 14 May 2008 and granted full NATO accreditation that October, has grown from those seven founders to 39 member nations by 2025 — NATO's only Centre of Excellence with representation from every alliance member (CCDCOE, About Us). The AI-in-armed-conflict research strand is one of its flagship legal projects, alongside the Tallinn Manual on cyber operations and the CyCon conference series (CCDCOE, "AI Meets the Laws of War"). At CyCon 2026 in Tallinn (26-29 May), AI "featured prominently across both the legal and technical tracks," with papers specifically examining how IHL considerations should be built into military AI procurement — over 600 senior officials and 21 peer-reviewed papers engaged the question directly (Belfer Center, 2026).
Steelmanning the Case
The underlying worry is legitimate. A battlefield-only compliance check assumes the legal risk in an autonomous or AI-assisted system is fixed at the point of use. It isn't. If a targeting model is trained on biased or stale data, if a cyber-AI tool is repurposed from a civilian codebase without re-testing, or if a system's behavior drifts after a software patch, the moment of greatest legal exposure may occur long before — or well after — a human ever pulls a trigger. Treating Article 36 review as a one-time gate, as most states currently do, creates exactly the kind of accountability gap Roscini describes. Regulators and militaries who want serious answers about IHL compliance for adaptive systems have a real problem to solve, not a hypothetical one.
Where the Proposal Overreaches
The risk is what "lifecycle oversight" becomes once it leaves a law review symposium and enters procurement bureaucracy. NATO militaries, including Estonia's own defense establishment, are trying to field AI-cyber capabilities fast enough to keep pace with adversaries who impose no equivalent legal review on themselves. A due-diligence regime that requires continuous re-certification through every software update — plausible in principle — risks becoming, in practice, a standing compliance tax that slows exactly the defensive capabilities NATO needs deployed quickest. Jimena Viveros's contribution to the same symposium pushes further still, calling for a "centralized, independent governance authority with verification power" spanning civilian and military AI alike — a proposal that, however well-intentioned, would layer a new international bureaucracy onto a field already governed by IHL, export controls and NATO's own accreditation processes.
The better path is closer to what Goussac and Liivoja actually propose: risk-calibrated, ongoing review scaled to how much a given system's behavior can drift, not a uniform lifecycle audit applied identically to every AI-enabled tool. A cyber-defense system's anomaly detector and an autonomous weapons platform do not carry the same accountability risk, and treating them identically wastes scrutiny on the former while doing nothing extra for the latter. CCDCOE's research agenda is right to open this question. What NATO members do with it — proportionate, risk-tiered review versus a blanket new compliance layer — will determine whether it strengthens deployed systems or just slows their fielding.