is adopted or mirrored across most major regulatory systems: directly in the EU (EN ISO 13855) and Switzerland (SN EN ISO 13855); through equivalent operator-protection duties in the United States (OSHA, 29 CFR § 1910.212); as binding law in the Eurasian Economic Union (Technical Regulation TR CU 010/2011); through national adoption of the underlying ISO/IEC standards in China (GB/T 15706, GB 5226.1, GB/T 16855.1); and through the same guarding tradition in Israel (Work Safety Ordinance 5730-1970). Their relevance is evidential: in every one of them, the interval between a protective signal and an irreversible outcome is treated as a measurable design parameter rather than an accident of circumstance.
Surrender is protected by law. That protection depends on a system's ability to stop in time.
The legal protection of surrender is not new. Its customary foundation predates Additional Protocol I. Article 23(c) of the 1907 Hague Regulations prohibits killing or wounding an enemy who, having laid down his arms or no longer possessing means of defence, has surrendered at discretion; the corresponding prohibition on attacking persons hors de combat is recognised as customary international humanitarian law. Article 41 of Additional Protocol I provides the clearest treaty formulation for States party to the Protocol, protecting a person who is recognised, or who in the circumstances should be recognised, as hors de combat, including a person who clearly expresses an intention to surrender. The underlying protection is therefore not a proposal created for autonomous systems. It is an existing rule whose practical operation must survive technological change.
But that right rests on a silent assumption: that once surrender is communicated, someone — or something — can actually stop in time. As long as a human operator makes the firing decision, this assumption usually holds. Human reaction time, however imperfect, provides the bridge between recognition and restraint.
Autonomous systems can break that bridge. When a machine's decision cycle outpaces human reaction time, surrender can be perfectly recognized and still be irrelevant — because no intervention arrives before the outcome is fixed. The failure is not one of recognition. It is one of arrestability: the system's structural capacity to be stopped within a human-relevant window of time.
This reframes the problem. Recognition is a necessary but secondary condition; arrestability is the precondition that gives recognition any legal weight at all.
The obligation itself is not something Human Flag is asking States to invent. It is already in force. Article 41 of Additional Protocol I prohibits attacks on persons hors de combat, and the corresponding customary rule binds States not party to the Protocol. Article 57(2)(b) requires an attack to be cancelled or suspended once it becomes apparent that its object is protected — a duty that presupposes an interval in which cancellation remains possible. Article 36 places the examination of that capacity at the stage of study, development, acquisition and adoption for States party, and comparable national review requirements apply elsewhere. What is missing is not a rule, but the recognition that an existing one has a temporal precondition.
That precondition is neither novel nor technically exotic. Wherever a machine can injure the people who operate it, the capacity to halt it within an interval compatible with human reaction is treated as an ordinary engineering requirement, specified, tested and documented in machine-safety law. The same capacity, applied to the recognition of a person attempting to surrender, is described as technically unattainable. It is not unattainable: it is a decision about whom the interval is built to protect.
The same treatment appears within military system-safety practice itself. Under MIL-STD-882E, whether software exercising authority over safety-significant functions leaves “time for predetermined safe detection and intervention” is the criterion that separates a semi-autonomous software control category from an autonomous one, and that classification determines the level of rigor required of the analysis and the authority at which residual risk must be accepted. The standard does not prohibit building a system that leaves no such interval. It requires that the choice be classified, analyzed and accepted at a named level of authority. Like the civil frameworks below, it protects the force operating the system rather than an adversary, and creates no humanitarian obligation.
The same structure appears, independently, wherever law governs machines that can injure. ISO 13855 fixes minimum safety distances by reference to approach speed, and is adopted or mirrored across most major regulatory systems: directly in the EU (EN ISO 13855) and Switzerland (SN EN ISO 13855); through equivalent operator-protection duties in the United States (OSHA, 29 CFR § 1910.212); as binding law in the Eurasian Economic Union (Technical Regulation TR CU 010/2011); through national adoption of the underlying ISO/IEC standards in China (GB/T 15706, GB 5226.1, GB/T 16855.1); and through the same guarding tradition in Israel (Work Safety Ordinance 5730-1970). Their relevance is evidential: in every one of them, the interval between a protective signal and an irreversible outcome is treated as a measurable design parameter rather than an accident of circumstance. That convergence indicates the effectiveness problem is structural.