- Should a human approve every target an AI selects?
- What is the difference between a human in the loop, on the loop and off the loop?
- Is a human approval at the last step enough to make a machine's decision ours?
No treaty requires it, and the draft that would have has just lost the clause. The Washington Post reported on 26 September 2026 that at United Nations talks in Geneva the American and Russian delegations removed a provision requiring humans to review targets developed by AI before a strike. The next morning ABC News in Australia described an autonomous aircraft firing an air-to-air missile after a human in a second aircraft gave the final authorisation, under a Defence policy that names the accountable people. Between the two sits the question a board, a minister or a producer is asking: is a human approval enough. The evidence on human checking says approval is necessary and not sufficient. A person asked to confirm a machine’s choice under time pressure tends to confirm it. The decisions that hold are made earlier: which targets a machine may propose at all, who may refuse one, and what the humans must still be able to judge unaided.
What was removed in Geneva, as reported#
Pranshu Verma’s account in The Washington Post, read here in The Spokesman-Review’s syndication, rests on three people familiar with the negotiations and documents the paper reviewed. Over roughly fifteen hours at the Convention on Certain Conventional Weapons talks in early September, diplomats from the two countries, each with about ten lawyers against half that for other delegations, struck out language requiring autonomous weapons to operate in a “predictable” and “reliable” manner, a clause on ethical considerations, and the provision on human review of AI-developed targets before a strike. One of the three called it “death by a thousand paper cuts”. Verity Coyle of Human Rights Watch told the paper: “It could mean machines can make life-and-death decisions without human control.” Richard Lennane of the International Committee of the Red Cross told the paper that the point of a treaty was setting norms and influencing behaviour rather than punishment. Nicole van Rooijen of Stop Killer Robots said the two states “have the power to block any significant progress”. Neither government commented to the paper. States meet again in Geneva in November to decide whether the talks become a mandate for a binding instrument.
What the doctrines say instead#
The rule most armies point to is national, not international. The United States Department of Defense’s Directive 3000.09, reissued on 25 January 2023, requires that autonomous and semi-autonomous weapon systems be designed to allow commanders and operators to exercise “appropriate levels of human judgment over the use of force”. It does not say every target must be approved by a person; it says the level of judgement must be appropriate, and leaves appropriate to be decided in each case. The Post reported that the directive is under revision, that a June memorandum from the President ordered an update within ninety days, and that none had been published by late September. Australia’s policy, as quoted by Tom Lowrey in ABC News on 27 September, goes one step further and names the people: “Human judgement and accountability is central to lawful, legitimate and responsible use of AI, and designated Defence personnel [Accountable Officers] will always be accountable for its use, decisions and outcomes.” Both documents answer the question who is responsible. Neither answers the question this page asks, which is what the responsible person is able to do at the moment of decision.
The Ghost Bat, and where the human sat#
The ABC piece describes a test in South Australia in December in which the MQ-28 Ghost Bat, an uncrewed aircraft, fired an air-to-air missile at a target. An operator in an E-7 Wedgetail instructed the aircraft to engage, its system developed the engagement plan, and, in the words of the report, “the operator in the E7 gave a final authorisation before the missile was launched”. Air Marshal Stephen Chappell, Chief of Air Force, told the ABC that the aircraft runs on deterministic programming rather than on AI: “It is not making up its own game plan itself. Therefore we have full confidence in what it will do and what it won’t do.” That is the arrangement the literature calls a human on the loop: the machine proposes and prepares, a person can stop it, and the person’s approval is the last step. The same article reports that the Defence Force told parliament its Maven Smart decision-support system runs in a sandbox unconnected to wider networks, and quotes Malcolm Davis of the Australian Strategic Policy Institute describing such systems as a “silicon commander”. Georgia Hinds, a legal adviser at the ICRC, told the ABC: “We continue to see conflicts that cause unacceptable levels of civilian harm, and that’s in some of the conflicts that have the most technologically sophisticated means of warfare.”
Why a final approval is weaker than it sounds#
Aina Turillazzi of the Australian National University’s Strategic and Defence Studies Centre gave the ABC the sentence this page turns on: “Petrov was right. The risk with AI decision support isn’t that the machine malfunctions, but it’s that under pressure, people stop assessing the evidence and start simply confirming the recommendation or the evidence.” Stanislav Petrov was the Soviet officer who in September 1983 judged a satellite warning of incoming American missiles to be a false alarm, against the system in front of him. The behaviour Turillazzi describes has a name and a body of measurement, set out on what is automation bias: people given a machine recommendation accept it more often than the recommendation deserves, and the effect grows with time pressure, workload and the machine’s past record of being right. The arithmetic of approval at speed is on can a human approve an AI decision at machine speed: a checker who cannot keep up stops checking and starts signing. And the case in which an AI-generated document nearly moved a real operation is on what the military AI near miss means for your organisation. Read together, they say that “a human approved it” describes a button being pressed and says nothing about whether a judgement was made.
The argument for the person, and its limit#
Joe Lonsdale, a Palantir co-founder and an investor in Anthropic, put the opposite case at a Reuters conference in Austin on 25 September, Reuters reported: “There’s always a person responsible who is in charge of whatever system they studied, worked on and approved.” He added: “It’s very easy from the outside to judge these things when you’re not there in the fog of war.” The first sentence is right as a description of accountability and is the Australian policy in one line. Its limit is the one Turillazzi names. A person can be responsible for a decision they were not, in the moment, able to make; the record of automation bias is a record of that gap between who signs and who judges. Responsibility without capability is the condition the weapons literature’s phrase, meaningful human control, and its regulatory cousin, meaningful human oversight, exist to rule out.
The decision that is made before the target appears#
If approval at the last step cannot carry the weight, the weight moves earlier, and that is where this site’s position sits for a ministry and for a company alike. The risk that can be measured is in the handover of a decision to a machine and what happens to the humans’ judgement afterwards; the decision an organisation controls is which decisions a machine may make at all, who can stop each one, what people must remain able to do, and how anyone would know it went wrong. In the weapons case that is four questions written down in advance: which classes of target a system may propose and which it may never touch, the red lines; who may refuse a proposal without penalty and how long they have; what the approving officer must be able to establish for themselves, from evidence the machine did not produce, before pressing anything; and what would tell the command afterwards that the machine was wrong and the person confirmed it anyway. The Australian test answers the first two in part and the ABC report is silent on the last two. The Geneva text, as reported, has just removed the international version of the first. Every one of them is a decision a human institution takes before the first target appears, which is the argument of Rules Before Tools.
What this does not show#
The Post’s account is of provisions removed, from three unnamed people and documents the paper saw; the full negotiating text is not public and this page has not read it, so what the revised text still requires of human judgement is not established here. Nothing in the ABC report says how much time the Wedgetail operator had, what they could see, or what they were told; a final authorisation may have been a considered judgement or a confirmation, and the report cannot tell the two apart. The automation-bias evidence comes from clinical, aviation and laboratory settings and from one military near miss, and has not been measured in live targeting. Directive 3000.09 is under revision and the version described here may not be the one in force by the time this is read. Lonsdale’s remarks are a position, not a finding. What the record does show is that the one safeguard everyone can agree to name, a human approval, is the one the evidence on human checking says least about.
Essay · SS-2026-364
Hirji, R. (2026). Should a human approve every target an AI selects?. The SuperSkills evidence base, SS-2026-364. https://thesuperskills.com/research/should-a-human-approve-every-target-an-ai-selects. Last reviewed 27 September 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work