Estonia Estonia CCDCOE cyber defence NATO

Tallinn Manual 3.0 Should Answer the AI and Cyber Questions Armies Are Already Facing, Not Pause for Treaty Talks

West Point's CyCon 2026 series, drawing on Tallinn discussions, shows that procurement, lifecycle legal review and digital emblems can govern military AI now.

Tallinn's Cyber-Law Agenda in Numbers People of Internet Research · Estonia 4 Articles of War series parts Lieber series drawn from CyCon 202… 5 years Tallinn Manual 3.0 timeline Project launched in 2021 as a five… ~4 years Digital emblem consultation period ICRC consulted states and experts … 515,000+ People in 2022 ICRC breach Vulnerable people whose data was c… peopleofinternet.com
Tallinn's Cyber-Law Agenda in Numbers People of Internet Research · Estonia 4 Articles of War series parts 5 years Tallinn Manual 3.0 timeline ~4 years Digital emblem consultation per… 515,000+ People in 2022 ICRC breach peopleofinternet.com

Key Takeaways

On September 9, 2026, NATO's Cooperative Cyber Defence Centre of Excellence in Tallinn highlighted a four-part "Articles of War" series from the Lieber Institute at West Point. The series comes out of discussions at the 18th International Conference on Cyber Conflict (CyCon), held in Tallinn in 2026. It lands while the same Tallinn centre is drafting Tallinn Manual 3.0. The series' central lesson is that existing law can already discipline military AI and cyber operations. The tools that work are practical ones: contracts, testing, review and technical standards.

The strongest case for tighter rules

The case for binding, AI-specific limits is serious. In the series' opening essay, Rain Liivoja writes that AI is increasing the speed, autonomy and sophistication of cyber conflict. AI systems are also themselves targets. Despite popular claims that AI will "fight the fog of war," he notes that the conference acknowledged AI "may in fact create a fog of war of its own." Speed and opacity strain the human judgment that international humanitarian law (IHL) assumes. Liivoja also flags the "absence of anything approximating a consensus as to the legal consequences of particular novel conduct" on what counts as a cyber attack. If commanders cannot tell when a cyber operation crosses the legal threshold, a treaty-first argument has real force.

Why procurement is the better lever

The series' most useful contribution answers that worry without waiting for a treaty. Anke Allenhöfer argues that procurement lets states "translate legal and policy objectives into concrete technical and contractual requirements." IHL sets principles such as distinction and proportionality. It does not prescribe engineering. The decisions that determine compliance, including software architecture, training data and test design, are made long before deployment. A contract can require legal reviews, defined test regimes and continuing weapons review as a system is updated.

A related essay by Maria Tolppa makes a similar point. Legal review has to follow a capability across its whole lifecycle, and a human "in the loop" is not enough unless that person has the time and authority to override the machine.

This is proportionate regulation. It targets the point where risk is created, and it works through existing legal duties. It also applies to the defence industry that Estonia and its NATO allies depend on for innovation. A blanket moratorium or a vague new prohibition would hit the same suppliers without saying what a compliant system looks like. One caveat: Allenhöfer's piece is prescriptive rather than empirical. It offers no testing metrics, so the approach still needs to be evaluated in practice.

The cyber attack definition problem

The definitional dispute matters because IHL protections attach to "attacks." Under the Tallinn Manual approach, a cyber attack takes its meaning from the definition of an attack in Article 49(1) of Additional Protocol I. Whether that covers operations that disable a hospital's network without physical damage, or that delete data, is where consensus is missing. Tolppa's essay observes that cyber capabilities are now "woven into communications, logistics, targeting, and command," so the legal categories are being stretched by operations that no longer sit in a separate cyber box. A separate Lieber essay by Colonel Inna Zavorotko of Ukraine's Ministry of Defence looks at how IHL operates across that interconnected battlespace, drawing on Ukraine's war experience.

This is where Tallinn Manual 3.0 can earn its keep. The CCDCOE says the project was launched in 2021 as a five-year venture. It is directed by Professor Michael Schmitt, with Liis Vihul and Marko Milanović as co-general editors. It will weigh state practice and official statements alongside scholarship. It is a non-binding scholarly study, not a treaty, and its value is in stating clearly where states agree and where they do not. For a technology moving this fast, a candid map of disagreement is more useful than false consensus.

Medical infrastructure: a standards fix

The series also covers the ICRC's digital emblem. The ICRC's project page describes it as extending the protective function of the red cross, red crescent and red crystal into cyberspace by marking the digital infrastructure of hospitals. It says the ICRC chose the Authentic Digital Emblem approach after nearly four years of consultations with states and experts. Geneva Solutions reported on July 10, 2026 that the ICRC and Microsoft had moved it into an operational, field-testing phase. Protected systems broadcast digitally signed messages. The same report notes the ICRC's own 2022 breach exposed data on more than 515,000 vulnerable people, and it quotes ICRC director Pierre Krähenbühl on unresolved questions about reliability, authentication and governance.

The emblem is a good template for regulation. It is a technical standard developed with industry and tested in the field, and it does not depend on a new ban. It will not stop a determined attacker, and it depends on adversaries being willing to respect it. But it makes a violation deliberate rather than accidental, and that is the kind of evidence IHL accountability needs.

What Tallinn should do

Three recommendations follow. First, Tallinn Manual 3.0 should say explicitly that legal review is a lifecycle obligation covering updates and retraining, not a one-time gate. Second, it should treat the disabling of medical and humanitarian digital services as a serious harm regardless of the label "attack," so that the definitional dispute does not leave hospitals exposed. Third, states should adopt procurement clauses and open technical standards now, and report what they learn. Estonia's position is a strong one for this. It hosts the centre that convenes the experts and has a cyber-defence sector that builds and buys the systems in question. Rules that are specific, testable and tied to real contracts will protect civilians better than sweeping prohibitions, and they leave room for the defensive innovation that small, digitally exposed states rely on.

Sources & Citations

  1. NATO CCDCOE (Tallinn)
  2. CCDCOE: The Tallinn Manual
  3. Lieber Institute: CyCon Comes of (AI) Age (Liivoja)
  4. Lieber Institute: Governing Responsible Military AI Through Defense Procurement (Allenhöfer)
  5. ICRC: Digital Emblem Project
  6. Geneva Solutions: ICRC and Microsoft launch digital emblem