← Research
Research · Question

Should a human approve every target an AI selects?

What was removed in Geneva, what the doctrines say instead, an autonomous aircraft with a human on the loop, and the evidence that a final approval under pressure tends to become a confirmation.

Last reviewed: 27 September 2026 · Next review due: 27 September 2027

No treaty requires it: The Washington Post reported on 26 September 2026 that the US and Russia removed a human-review clause from the UN text on autonomous weapons. Australia's Defence Force had a human give final authorisation before an uncrewed aircraft fired. Why that approval is necessary and not sufficient. An evidence review by Rahim Hirji; every figure resolves to a graded entry in the evidence base that says what it does not show.

Questions this page answersQuestion this page partly answersAll 1024 questions this research covers

No treaty requires it, and the draft that would have has just lost the clause. The Washington Post reported on 26 September 2026 that at United Nations talks in Geneva the American and Russian delegations removed a provision requiring humans to review targets developed by AI before a strike. The next morning ABC News in Australia described an autonomous aircraft firing an air-to-air missile after a human in a second aircraft gave the final authorisation, under a Defence policy that names the accountable people. Between the two sits the question a board, a minister or a producer is asking: is a human approval enough. The evidence on human checking says approval is necessary and not sufficient. A person asked to confirm a machine’s choice under time pressure tends to confirm it. The decisions that hold are made earlier: which targets a machine may propose at all, who may refuse one, and what the humans must still be able to judge unaided.

The answer, in one line

No.

Share as a card

What was removed in Geneva, as reported#

Pranshu Verma’s account in The Washington Post, read here in The Spokesman-Review’s syndication, rests on three people familiar with the negotiations and documents the paper reviewed. Over roughly fifteen hours at the Convention on Certain Conventional Weapons talks in early September, diplomats from the two countries, each with about ten lawyers against half that for other delegations, struck out language requiring autonomous weapons to operate in a “predictable” and “reliable” manner, a clause on ethical considerations, and the provision on human review of AI-developed targets before a strike. One of the three called it “death by a thousand paper cuts”. Verity Coyle of Human Rights Watch told the paper: “It could mean machines can make life-and-death decisions without human control.” Richard Lennane of the International Committee of the Red Cross told the paper that the point of a treaty was setting norms and influencing behaviour rather than punishment. Nicole van Rooijen of Stop Killer Robots said the two states “have the power to block any significant progress”. Neither government commented to the paper. States meet again in Geneva in November to decide whether the talks become a mandate for a binding instrument.

What the doctrines say instead#

The rule most armies point to is national, not international. The United States Department of Defense’s Directive 3000.09, reissued on 25 January 2023, requires that autonomous and semi-autonomous weapon systems be designed to allow commanders and operators to exercise “appropriate levels of human judgment over the use of force”. It does not say every target must be approved by a person; it says the level of judgement must be appropriate, and leaves appropriate to be decided in each case. The Post reported that the directive is under revision, that a June memorandum from the President ordered an update within ninety days, and that none had been published by late September. Australia’s policy, as quoted by Tom Lowrey in ABC News on 27 September, goes one step further and names the people: “Human judgement and accountability is central to lawful, legitimate and responsible use of AI, and designated Defence personnel [Accountable Officers] will always be accountable for its use, decisions and outcomes.” Both documents answer the question who is responsible. Neither answers the question this page asks, which is what the responsible person is able to do at the moment of decision.

The Ghost Bat, and where the human sat#

The ABC piece describes a test in South Australia in December in which the MQ-28 Ghost Bat, an uncrewed aircraft, fired an air-to-air missile at a target. An operator in an E-7 Wedgetail instructed the aircraft to engage, its system developed the engagement plan, and, in the words of the report, “the operator in the E7 gave a final authorisation before the missile was launched”. Air Marshal Stephen Chappell, Chief of Air Force, told the ABC that the aircraft runs on deterministic programming rather than on AI: “It is not making up its own game plan itself. Therefore we have full confidence in what it will do and what it won’t do.” That is the arrangement the literature calls a human on the loop: the machine proposes and prepares, a person can stop it, and the person’s approval is the last step. The same article reports that the Defence Force told parliament its Maven Smart decision-support system runs in a sandbox unconnected to wider networks, and quotes Malcolm Davis of the Australian Strategic Policy Institute describing such systems as a “silicon commander”. Georgia Hinds, a legal adviser at the ICRC, told the ABC: “We continue to see conflicts that cause unacceptable levels of civilian harm, and that’s in some of the conflicts that have the most technologically sophisticated means of warfare.”

Why a final approval is weaker than it sounds#

Aina Turillazzi of the Australian National University’s Strategic and Defence Studies Centre gave the ABC the sentence this page turns on: “Petrov was right. The risk with AI decision support isn’t that the machine malfunctions, but it’s that under pressure, people stop assessing the evidence and start simply confirming the recommendation or the evidence.” Stanislav Petrov was the Soviet officer who in September 1983 judged a satellite warning of incoming American missiles to be a false alarm, against the system in front of him. The behaviour Turillazzi describes has a name and a body of measurement, set out on what is automation bias: people given a machine recommendation accept it more often than the recommendation deserves, and the effect grows with time pressure, workload and the machine’s past record of being right. The arithmetic of approval at speed is on can a human approve an AI decision at machine speed: a checker who cannot keep up stops checking and starts signing. And the case in which an AI-generated document nearly moved a real operation is on what the military AI near miss means for your organisation. Read together, they say that “a human approved it” describes a button being pressed and says nothing about whether a judgement was made.

The argument for the person, and its limit#

Joe Lonsdale, a Palantir co-founder and an investor in Anthropic, put the opposite case at a Reuters conference in Austin on 25 September, Reuters reported: “There’s always a person responsible who is in charge of whatever system they studied, worked on and approved.” He added: “It’s very easy from the outside to judge these things when you’re not there in the fog of war.” The first sentence is right as a description of accountability and is the Australian policy in one line. Its limit is the one Turillazzi names. A person can be responsible for a decision they were not, in the moment, able to make; the record of automation bias is a record of that gap between who signs and who judges. Responsibility without capability is the condition the weapons literature’s phrase, meaningful human control, and its regulatory cousin, meaningful human oversight, exist to rule out.

The decision that is made before the target appears#

If approval at the last step cannot carry the weight, the weight moves earlier, and that is where this site’s position sits for a ministry and for a company alike. The risk that can be measured is in the handover of a decision to a machine and what happens to the humans’ judgement afterwards; the decision an organisation controls is which decisions a machine may make at all, who can stop each one, what people must remain able to do, and how anyone would know it went wrong. In the weapons case that is four questions written down in advance: which classes of target a system may propose and which it may never touch, the red lines; who may refuse a proposal without penalty and how long they have; what the approving officer must be able to establish for themselves, from evidence the machine did not produce, before pressing anything; and what would tell the command afterwards that the machine was wrong and the person confirmed it anyway. The Australian test answers the first two in part and the ABC report is silent on the last two. The Geneva text, as reported, has just removed the international version of the first. Every one of them is a decision a human institution takes before the first target appears, which is the argument of Rules Before Tools.

What this does not show#

The Post’s account is of provisions removed, from three unnamed people and documents the paper saw; the full negotiating text is not public and this page has not read it, so what the revised text still requires of human judgement is not established here. Nothing in the ABC report says how much time the Wedgetail operator had, what they could see, or what they were told; a final authorisation may have been a considered judgement or a confirmation, and the report cannot tell the two apart. The automation-bias evidence comes from clinical, aviation and laboratory settings and from one military near miss, and has not been measured in live targeting. Directive 3000.09 is under revision and the version described here may not be the one in force by the time this is read. Lonsdale’s remarks are a position, not a finding. What the record does show is that the one safeguard everyone can agree to name, a human approval, is the one the evidence on human checking says least about.

Essay · SS-2026-364

Cite this page

Hirji, R. (2026). Should a human approve every target an AI selects?. The SuperSkills evidence base, SS-2026-364. https://thesuperskills.com/research/should-a-human-approve-every-target-an-ai-selects. Last reviewed 27 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Does international law require a human to approve every AI-selected military target?

No. There is no binding treaty on autonomous weapons, and The Washington Post reported on 26 September 2026 that at the UN Convention on Certain Conventional Weapons talks in Geneva the American and Russian delegations removed a draft provision requiring humans to review AI-developed targets before a strike, along with language on predictable and reliable operation and on ethics. States meet again in November.

What does the US directive on autonomous weapons require?

Department of Defense Directive 3000.09, reissued on 25 January 2023, requires autonomous and semi-autonomous weapon systems to be designed so that commanders and operators can exercise appropriate levels of human judgment over the use of force. It does not require a human approval of every target. The Post reported it is under revision and no new version had been published by late September 2026.

What is the difference between a human in the loop, on the loop and off the loop?

In the loop, a person makes each engagement decision. On the loop, the machine proposes and prepares and a person supervises and can stop it, as in the Ghost Bat test ABC News described on 27 September 2026, where an operator in a second aircraft gave the final authorisation. Off the loop, the machine acts with no intervention. The evidence on automation bias is that on-the-loop approval under pressure tends to become confirmation.

Why is a human approving an AI's target not enough on its own?

Because approval under time pressure and workload tends to become confirmation, the pattern human-factors research calls automation bias, and a person can be accountable for a decision they were not able, in the moment, to make. The decisions that hold are made earlier: which targets a system may propose at all, who may refuse one without penalty, what the approver must establish from independent evidence, and how anyone would know afterwards that the machine was wrong and the person agreed.

In this hub

Judgement, oversight and accountability

Who decides, who checks, and who is answerable when the machine was involved.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Four decisions written down before any system proposes an action with consequences, which classes it may propose and which it may never touch, who may refuse without penalty and in what time, what the approver must establish from evidence the machine did not produce, and how the organisation would learn the machine was wrong and the person agreed, is the engagement. Board advisory.

This argument is one a board usually meets for the first time in the room. There is AI keynote for boards and leadership offsites, and the full range of topics and audiences.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.