Editors’ note: This is the ninth post in a series dedicated to Lethal Autonomous Weapons Systems (LAWS) and the questions of human oversight and legal accountability under international humanitarian law. Previous posts have focused on LAWS, China, Russia, the United States, and Europe. The second part of the series examines defense industry practices. It analyzes how hardware developers, software providers, and manufacturers approach the integration of law of armed conflict requirements into autonomous combat systems in the United States (see here and here), China, Europe, and Israel.
In May 2026, in a direct response to four years of rapid battlefield innovation in Ukraine, the European Commission opened the call for founding members of the EU-Ukraine Drone Alliance. The initiative aims to bring together Ukrainian operational experience and European industrial capacity to speed up the development and production of low-cost, attritable autonomous systems, complemented by the June 2026 rollout of the Ukraine Support Loan aimed at drone procurement.
This milestone in Europe’s post-2022 “drone awakening” underscores a significant shift that has, after years of planning and delays, gained momentum and may finally be ready to yield tangible results. The continent’s defense industry is no longer merely adapting legacy platforms with after-the-fact law of armed conflict (LOAC) adjustments, but strives to fast-track and embed the principles of distinction, proportionality, precaution, and accountability into the design of systems slated for mass deployment.
Compliance by design, as used in this series, refers to integrating LOAC obligations for autonomous weapons systems into engineering, procurement, and lifecycle management from the initial design phases of system development. It requires the translation of legal duties into concrete technical features, including audit logs that support post-incident accountability, explainable models that assist operators in conducting distinction and proportionality assessments, and fail-safe mechanisms that preserve meaningful human control (MHC) over lethal decisions.
Instead of treating legal obligations as external hurdles, compliance by design weaves LOAC compliance directly into the engineering workflow, mapping specific legal duties onto the system’s technical requirements and design specifications. For example, the duty to distinguish between combatants and civilians translates into accuracy benchmarks for a system’s sensors and targeting algorithms. Similarly, proportionality dictates that a system must be capable of predicting collateral damage before engaging a target.
The requirement of precaution is hard-coded through default behaviors that automatically abort or de-escalate whenever the system’s confidence falls below set thresholds. Although MHC has not yet been codified as a formal legal term in treaty law, it has undoubtedly emerged as a cornerstone of European policy, reflected in EDF funding conditions, national Article 36 reviews, and successive parliamentary resolutions.
Indeed, the European Parliament has explicitly and repeatedly called for binding requirements ensuring meaningful human oversight over lethal decisions, a standard that several member States are now embedding directly into national procurement frameworks. Although no specific treaty provision spells it out, in practice policy-driven tightening of this kind creates a de facto legal obligation for defense contractors.
The distinction between human-in-the-loop systems requiring affirmative human authorization for each engagement, human-on-the-loop configurations in which a supervisor retains authority to intervene, and fully autonomous human-out-of-the-loop operations constitutes a foundational element of LOAC compliance assessments. Thus far, European policy instruments favored human-in-the-loop or tightly circumscribed human-on-the-loop arrangements for decisions involving lethal force. However, the conflicts of the past years have made it quite clear that the operational demands in high-tempo environments push towards more permissive allocations of autonomy. Clarifying which level applies to particular functions, such as target selection versus engagement timing, is essential for precise legal review under Article 36 and for translating legal requirements into system design.
The European Defense Industry Landscape and LOAC Context
Despite decades-old European recognition that greater scale and integration are essential for global competitiveness, not unlike most other sectors on the continent, the defense industry continues to operate within a landscape marked by longstanding fragmentation across national borders. This is despite Brussels-promoted collaborative programs gaining momentum among leading prime contractors and specialized small and medium-sized enterprises (SMEs).
Major companies such as Airbus, Thales, Leonardo, Rheinmetall, BAE Systems, and Saab are working on Europe’s most ambitious defense initiatives. These include the long-troubled Future Combat Air System (FCAS), as well as the Main Ground Combat System (MGCS). Alongside the expanding pipeline of projects backed by the European Defence Fund (EDF), flagship initiatives offer a rare window as they allow developers to embed LOAC compliance into the procurement and engineering cycles from the outset.
By forcing industry and policymakers to confront the reality of LOAC compliance in high-intensity, technology-driven operations, the Russo-Ukrainian War has accelerated this shift. The conflict has shown how attritable autonomous systems are reshaping key aspects of warfare through rapid adaptation, cost asymmetry, and persistent intelligence, surveillance, and reconnaissance (ISR) and strike capabilities. Yet despite all their—in no small part already proven—potential, it is important to bear in mind that drones remain powerful tactical tools rather than a standalone strategic revolution, and their effectiveness still relies on combined-arms integration, resilient logistics, and electronic warfare countermeasures.
Ukrainian operations continue to illustrate both the tactical potency of low-cost FPV drones and loitering munitions when employed in massed, decentralized formations, and the legal hazards that accompany high-tempo autonomy in dense electronic warfare conditions where rates of fratricide and civilian harm have risen considerably. Initially uncertain and slow moving, European industry has been gathering steam and responding by embedding conclusions drawn from the war into development pipelines, prioritizing architectures that combine rapid producibility and scalability with the technical safeguards required for LOAC compliance. Among these are resilient communications links, automatic fallback to direct human control under jamming, and modular designs that permit rapid software iteration on the basis of real-time battlefield data.
The same drive is also visible in Europe’s broader industrial initiatives. These aim at strengthening strategic autonomy, such as the May 2026 call for founding members of the EU-Ukraine Drone Alliance, an effort spearheaded by industry to combine Ukrainian operational expertise with European manufacturing capacity. The Alliance is closely linked to the European Drone Defence Initiative and the Low-Cost Effectors and Autonomous Platforms (LEAP) program involving France, Germany, Italy, Poland, and the United Kingdom.
The framework in which these developments are taking place continues to prioritize LOAC compliance. National Article 36 weapons-review obligations, reinforced by European Court of Human Rights jurisprudence on State responsibility and the use of force, consistently stress the importance of MHC over lethal decisions. This jurisprudence is increasingly shaping expectations around accountability and oversight, while EU statements reinforce the same human-centered approach. In contrast to the more permissive approaches seen in countries like China, these trends set Europe apart by placing a particularly strong institutional emphasis on embedding LOAC compliance into defense innovation.
Regulatory and Policy Framework
As is characteristic of many domains of EU governance, Europe’s regulatory landscape for military AI is notably fragmented. This fragmentation is clearly visible at the supranational level, where the EU’s Artificial Intelligence Act does not apply to systems developed or used exclusively for military, defense, or national security purposes.
While this carve-out preserves Member States’ sovereignty in defense matters, it simultaneously opens a significant regulatory gap for military AI, leaving dual-use technologies subject to differing standards according to their ultimate application. Consequently, the Act’s risk-based framework does not directly govern advanced programs such as the grounded FCAS remote carriers or MGCS’s AI-enabled targeting functions. However, its civilian standards still exert indirect pressure through supply-chain certification and broader conformity requirements.
Complementing the AI Act, the EDF imposes explicit ethical and legal conditions on the projects it funds. The EDF Regulation prohibits support for lethal autonomous weapons lacking MHC over selection and engagement of human targets. It also requires all funded actions to comply with relevant EU, national, and international law, including the Charter of Fundamental Rights. Similar requirements appear in related instruments like the European Defence Industry Reinforcement through common Procurement Act and Act in Support of Ammunition Production, which tie funding eligibility to demonstrated human oversight and Article 36 weapons-review processes. Taken together, these mechanisms make compliance by design a mandatory contractual requirement for any entity seeking EU funding.
National variations do persist within this framework. France and Germany, for example, integrated Article 36 reviews early in the development cycles of FCAS and MGCS, while the United Kingdom has, post‑Brexit, aligned its procurement practices with NATO’s emerging principles on responsible military AI use. Across the board, export control regimes under the EU Common Position on arms exports further reinforce early integration of LOAC features such as audit logs and explainability. Taken together, these initiatives point to a distinct European approach, one that prioritizes human-centered design while still responding to the operational realities reflected in Ukraine-derived programs such as LEAP.
A central practical expression of this approach is the Article 36 weapons review process. In Europe and globally, these reviews are carried out by multidisciplinary teams that bring together legal advisers, engineers, and operational experts, and they begin assessing new systems from the concept stage onward.
Despite these structured review processes, several persistent challenges remain. These include how to assess systems that keep changing after deployment because of software updates, how to handle swarm effects that only become visible once the system is used in real operations, and how to coordinate reviews across multinational programs when the countries involved apply different legal standards.
Implementation in Practice
Implementation of compliance by design is most evident in Europe’s flagship collaborative programs, where industry consortia are translating regulatory and ethical requirements into specific engineering features. FCAS, or more precisely its fighter component, was the most ambitious example of this approach. Even though the aircraft itself is now an ill-fated piece of military development history, its conceptual framework is likely to remain the clearest illustration of European compliance by design thinking for some time. Led by Airbus, together with Dassault Aviation, Thales, and Leonardo, FCAS was conceived as a networked “system of systems” in which a next-generation crewed fighter would operate alongside families of remote carriers, a concept that, like much of the broader drone field, has been gaining traction for years.
Remote carriers are designed to conduct complex mission profiles including sensor fusion, targeting support, and kinetic effects with a high degree of autonomy, and the FCAS program consistently stressed that all lethal decisions were to remain under MHC. To achieve this, the Article 36 weapons-review process was tied directly to program milestones. Industry partners integrated these considerations from the conceptual phase. Formal legal sign-off was required before finalizing major design choices such as how much autonomy to allow, which sensor suite to use, or how broadly to define the engagement envelope. This resulted in the embedding of audit logs, explainable AI modules for distinction and proportionality assessments, and fail-safe overrides that preserve operator intervention even in contested electromagnetic environments.
While simulation-based testing is essential for early validation, it has obvious limits when it comes to capturing the full complexity of real-world combat, especially in conditions involving electronic warfare, deception, and unexpected swarm behavior. As such, testing proportionality algorithms requires more than technical benchmarks alone, as it also calls for legal and ethical judgment about what counts as acceptable collateral damage across different operational settings. Efforts are increasingly moving toward hybrid approaches that combine high fidelity simulation, live exercises, and red teaming with legal observers present, in order to get closer to the conditions under which legal review must ultimately stand or fall.
In practice, explainable AI tools designed to support distinction can give operators confidence scores and feature visualizations that show why a target was classified as a combatant. Audit logs are intended to capture sensor inputs, algorithmic decisions, operator commands, and system states while preserving cryptographic integrity, an area where ideas flourish, thereby creating a record that can later support legal review. There is a whole range of failsafe measures that may include geofencing, automatic aborts when the data link falls below a set threshold, or mandatory re-confirmation before engagement in high-risk areas.
A second prominent example appears in the rapid fielding of loitering munition systems by Rheinmetall. In April 2026, the German Bundeswehr awarded Europe’s fourth largest defense company a €2.4 billion framework contract for the FV-014 portable strike drone, which combines ISR and precision engagement capabilities. The system is designed for human-in-the-loop control: the operator remains engaged in the decision-making process at all times and retains the ability to observe, analyze targets, and abort the mission if conditions change. Rheinmetall has emphasized that this approach helps minimize collateral damage while enabling precise and effective engagement of critical threats. The design reflects broader industry and national efforts to ensure loitering munitions can deliver discriminate effects under rigorous legal and operational scrutiny, including Germany’s Article 36 weapons review requirements.
Challenges
Despite significant progress in embedding LOAC principles, the European defense industry still faces structural challenges that test how practical compliance by design truly is. The first is a conceptual paradox: the tension between applying rigorous, heavy compliance rules to exquisite multi-billion-euro platforms like MGCS, and the practical reality of fitting the same complex audit logs into fast-evolving €499+VAT expendable drones built for mass deployment.
The second challenge is the quintessential European problem, the continued fragmentation of the European Union’s defense industrial base, which leads to duplicated capabilities and inefficient procurement across member States.
In 2017, a comparison in the Munich Security Report drew significant attention when it showed that Europe operated 178 major weapon systems compared to only 30 in the United States. Nearly a decade has passed since, but Brussels’s efforts to reduce fragmentation and encourage joint procurement notwithstanding, the problem looms large.
While solutions remain elusive, the reasons for Europe’s persistent industrial fragmentation are quite clear. Nearly every member State still insists on maintaining the full spectrum of national capabilities: air power; armored forces; artillery; and now unmanned systems. This means a wide array of incompatible platforms. From main battle tanks alone, member States field no fewer than nineteen different systems, whereas the United States has long consolidated into a handful of standardized platforms.
In such a fragmented industrial base, embedding LOAC principles consistently by design becomes quite the challenge. Divergent national programs, different design cultures, and incompatible platforms all make it harder to develop common technical standards, share best practices for legal review, and ensure that compliance features are applied to the same high standard. Moreover, the legal and technical burden of building explainable AI and robust audit logs is high and falls especially hard on the specialist SMEs Europe depends on, which could well end up stifling the agile innovation Brussels is trying to encourage.
Yet fragmentation is only one part of a broader set of structural vulnerabilities. The spectre of supply chain fragility also looms large, a problem hardly unique to Europe. The United States, while benefiting from a far more consolidated defense industrial base dominated by a small number of prime contractors, still heavily depends on foreign suppliers for critical inputs. It imports more than 70% of its rare earths from China, and it also relies on Taiwan and South Korea for much of the advanced semiconductor manufacturing capacity needed for autonomous systems.
For compliance by design, this raw material dependence translates into vulnerabilities in system reliability and long-term performance. Rare earth elements are essential for the high-performance magnets, sensors, and actuators used in autonomous and AI-enabled systems. If this supply chain is disrupted or degraded, it can undermine the reliability and predictability that legal reviews and ongoing LOAC compliance rely on.
In Europe, these issues are exacerbated by the 35% cap on non-EU components under the European Defence Industry Programme, which still leaves complex verification challenges and associated LOAC risks in third-party transfer. Post-Ukraine tightening of arms-export rules under the EU Common Position on arms exports further strains the balance between accelerating aid to partners and maintaining strict compliance standards.
Dual-use spillover from civilian AI development under the AI Act creates additional gaps, as technologies developed for commercial applications feed into military systems without the same level of LOAC-specific safeguards. Accountability gaps become especially pronounced in high-tempo operations where electronic warfare can disrupt data links and compress decision timelines, challenging the maintenance of MHC. When an autonomous system fails, this ambiguity raises serious unresolved liability questions. It remains legally unclear whether responsibility lies with the commander who deployed the weapon, the operator who lost connection, or the defense contractor whose algorithm misidentified a civilian. As a result, verifying proportionality algorithms and bias mitigation measures in dynamic targeting scenarios remains difficult.
These challenges have shaped distinct national and multilateral approaches. Europe’s human-centric regulatory model differs from the United States’ innovation-driven approach, which places greater emphasis on the rapid deployment of autonomous capabilities. NATO’s emerging principles on responsible military AI highlight accountability, transparency, and human oversight, but stop short of setting binding limits on levels of autonomy. Since Brexit, the United Kingdom has followed a hybrid approach, bringing its procurement and responsible AI practices into line with NATO’s principles while retaining access to certain EU funding streams and contractual safeguards. As good as all of this sounds on paper, regulatory divergences create a serious practical friction. When an EU-developed system with strict, built-in human overrides is integrated into a joint NATO task force operating under more permissive autonomy thresholds, a major operational hurdle arises in determining which legal standard governs the engagement.
Conclusion
Europe has developed a relatively structured approach to compliance by design, in which legal obligations under the LOAC are increasingly translated into technical and contractual requirements from the earliest stages of development. Through Article 36 reviews, European Defence Fund conditions, and national procurement practices, European States have sought to embed principles of distinction, proportionality, and MHC directly into system architecture.
This model, however, faces a range of challenges and at present there is little consensus on how to solve them. Firstly, military AI is excluded from the EU AI Act; secondly, contractual standards of the EU do not always match NATO’s more flexible principles; and thirdly, dual-use technologies blur regulatory lines, leading to gaps and inconsistencies. These frictions are most visible in multinational programs where autonomy settings can vary depending on the end user, and by definition, all EU and NATO programs are multinational.
While it is impossible to predict exactly what the future holds, it is clear that Europe faces a momentous choice. It can either build on its regulatory and legal strengths to shape responsible military AI at scale, or risk seeing its influence gradually erode due to fragmentation, dual-use spillovers, and the operational pressures of high-intensity conflict. The future of European compliance by design will hinge on whether Brussels can close these gaps while keeping the human-centered standards that underpin its approach. Ultimately, the success of its model will depend on whether European policy can match the scale of its industrial ambition.
***
Dr Gerald Mako is a Research Affiliate at the Cambridge Central Asia Forum at Cambridge University.
The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.
Photo credit: RBC-Ukraine