International Law & Cyber Policy Experts - Silent Use-of-Force Gap
In 2017, a single cyber operation caused an estimated $10 billion in damage across three continents. The UK and US publicly attributed it to the Russian military.
Yet NO state called it a use of force. No one invoked the UN Charter’s gravest prohibitions. The responses were sanctions, indictments, and carefully worded condemnation.
I’ve spent the past months working on a piece about what that silence actually tells us. The conventional debate asks whether international law is adequate to govern cyber conflict. My answer? It is legally adequate, but operationally incomplete.
Three primary observations that shaped my thinking:
1. The attribution problem isn’t a legal gap. The tests are settled. The issue is satisfying them at machine speed - an incredibly difficult task.
States won’t invoke the rules that matter most. Even with confident attribution and massive destruction, victims consistently choose sanctions over legal characterization that might imply escalation. A framework whose gravest prohibitions go uninvoked governs only at its edges.
Sovereignty is quietly being privatized. A state’s capacity to resist attack now runs through commercial cloud regions, privately owned satellite constellations, and AI models governed by corporate licensing terms. The Charter’s state-centric architecture never contemplated this and I believe that this is precisely where the next decade of legal development will concentrate.
Full piece coming soon. If you work at the intersection of international law, cyber policy, or AI governance, I’d welcome your thoughts.
Brought to you by Sourcee
We find journo requests from across the web and deliver them directly to your inbox.