Surrender is protected by law. That protection depends on a system's ability to stop in time.
The legal protection of surrender is not new, and it does not originate in Additional Protocol I. Article 23(c) of the 1907 Hague Regulations prohibits killing or wounding an enemy who, having laid down his arms or no longer possessing means of defence, has surrendered at discretion; the Hague Regulations have long been recognised as reflecting rules of customary international law, including by the Nuremberg Tribunal and in the jurisprudence of the International Court of Justice. The corresponding prohibition on attacking persons hors de combat is customary and binds every party to an armed conflict, whatever it has ratified. For States party to Additional Protocol I, Article 41 provides the clearest treaty formulation, and adds an internal standard of recognisability: protection attaches not only to what is recognised, but to what, in the circumstances, should be recognised. The status is conditional in a specific way — it holds where the person abstains from hostile acts and does not attempt to escape. The condition is defined by conduct, not by inner intent.
The law also requires stopping. Under customary precautionary duties, and explicitly under Article 57 for States party, an attack must be cancelled or suspended when information emerging during its execution shows that its continuation is no longer lawful — including where a person has surrendered and is therefore no longer a lawful object of attack. The obligation already has a temporal structure. It presupposes that an engagement under way can still be halted.
What the law does not prescribe is a reaction time. It states the legal consequence once a relevant change of status is, or should be, recognised. It does not specify the interval in which that consequence can still be given effect.
The temporal problem is not new. Automated and autonomous functions make it more acute, by compressing the interval between recognition of a legally relevant change and an irreversible effect below the time required for effective intervention. Autonomy is an instance of the problem, not its foundation: the problem is temporal, and it arises wherever the speed of the process exceeds the speed of the response, whatever the underlying technology.
Much of the debate treats this as a problem of perception: can a system detect that a person is surrendering? That question is real, and difficult. But it is not the question this concept turns on. Assume perfect recognition. Assume the relevant change of status is detected at the earliest technically possible moment. The problem does not disappear — because if the time remaining before the effect becomes irreversible is shorter than the end-to-end time required to halt the action, the recognition is correct and operationally ineffective. Framing the issue as recognition invites a standing answer: perception is improving. That answer is not available here. Perception can improve indefinitely without gaining a single millisecond in stopping time.
Nor does the question depend on how a system is classified. Debate on autonomous weapons has centred on which systems fall within a given characterisation, and how much human involvement removes a system from it. Those questions matter, and they remain open. Whatever characterisation is eventually adopted, the same question applies: does the engagement process leave time for a legally relevant change of status to affect conduct before force becomes irreversible? A supervised system whose window is two seconds has the same problem as an unsupervised one. Formal labels do not answer that question.
The criterion does not require that force remain reversible up to the moment of impact. Where a human determines a specific engagement, the precaution is exercised before that engagement, and the point of no return that follows is a property of the means employed. But where a system carries out successive engagements whose individual circumstances were not determined when that human assessment was made, no individualised human assessment precedes the second engagement, or the third. What can still be determined in advance is the operational envelope — and the interval available for a legally relevant change of status to alter or halt the engagement before the point of no return is what sets the dimensions of that envelope, rather than a constraint verified within limits set on other grounds.
The structure is not unfamiliar. Machine safety law faces it directly. Where a hazardous action can produce irreversible effects faster than the minimum credible human response time for that configuration, the duty migrates to design: the European principle of safety integration prefers risks eliminated by design over instructions to the operator, and American machine-guarding law has never answered fast hazards with "react faster". Stopping performance is treated as a design quantity — the positioning of safeguards is calculated from standardised human approach speeds and system response times, not assumed. That migration, however, is dispersed across a design hierarchy, voluntary standards and category-specific rules; it is nowhere stated as a general criterion.
What transfers here is architectural, not normative. Industrial machinery is not designed to cause harm, and the duty owed to an operator is not the duty owed under the law of armed conflict. No obligation for the conduct of hostilities is derived from civil product-safety law. What carries over is the method — the comparison of two measurable windows, and the conclusion that where reaction is impossible, the law has always demanded design.
The same structure appears within military system-safety practice itself. Under MIL-STD-882E, whether software exercising authority over safety-significant functions leaves "time for predetermined safe detection and intervention" is the criterion that separates a semi-autonomous software control category from an autonomous one, and that classification determines the level of rigor required of the analysis and the authority at which residual risk must be accepted. The standard does not prohibit building a system that leaves no such interval. It requires that the choice be classified, analyzed and accepted at a named level of authority. Like the civil frameworks below, it protects the force operating the system rather than an adversary, and creates no humanitarian obligation.
The convergence is wide. ISO 13855 fixes minimum safety distances by reference to approach speed, and is adopted or mirrored across most major regulatory systems: directly in the EU (EN ISO 13855) and Switzerland (SN EN ISO 13855); through equivalent operator-protection duties in the United States (OSHA, 29 CFR § 1910.212); as binding law in the Eurasian Economic Union (Technical Regulation TR CU 010/2011); through national adoption of the underlying ISO/IEC standards in China (GB/T 15706, GB 5226.1, GB/T 16855.1); and through the same guarding tradition in Israel (Work Safety Ordinance 5730-1970). Their relevance is evidential: in every one of them, the interval between a protective signal and an irreversible outcome is treated as a measurable design parameter rather than an accident of circumstance. That convergence indicates the effectiveness problem is structural. The capacity to halt a machine within a humanly relevant interval is, in these frameworks, an ordinary engineering requirement — specified, tested and documented. The same capacity, applied to the recognition of a person attempting to surrender, is described as technically unattainable. It is not unattainable: it is a decision about whom the interval is built to protect.
A system is systemically arrestable when its capacity to halt a hazardous action does not depend on a human operator perceiving, evaluating, and intervening within the time window of that action. The criterion yields a hierarchy rather than a single requirement. First, the system should allow time: wherever feasible, it should be designed so that a humanly bridgeable interval exists between the onset of the action and the point of irreversibility. Second, where that is not achievable, the capacity to halt must reside in a mechanism whose own response time fits inside a window too short for human response. The second tier engages exactly when, and because, the first fails.
The criterion is therefore not a human-exclusion principle. It does not remove the operator's stop devices or diminish their role where the window permits their use; it ensures only that the last layer of stoppability does not depend on them. And it adds no obligation. It states the condition under which obligations that already exist can still be discharged.
Arrestability is a system property evaluated within a defined operational envelope. It can therefore be established before deployment: the minimum credible response time of the intervention chain, measured under specified conditions, set against the time remaining before effects become irreversible. For States party to Additional Protocol I, Article 36 provides the legal framework for examining the issue during the study, development, acquisition or adoption of a new weapon, means or method of warfare. For other States, the same technical question can be addressed through whatever national weapons-review, acquisition, procurement or safety processes are applicable.
This is also where arrestability differs evidentially from recognition. Whether a legally relevant status was correctly recognised in a particular event may depend on the information and circumstances of that event. Stopping performance, by contrast, can be measured in advance as a system property within a defined operational envelope. The two questions can therefore be examined separately: whether the relevant condition was recognised, and whether, once recognised, sufficient stopping capability remained to give that recognition effect.
If testing establishes in advance that, within a defined operational envelope, the system cannot respond before the relevant effect becomes irreversible, the limitation is no longer an unforeseen battlefield circumstance. It is a known characteristic of the design and its intended use. An impossibility encountered in the field is a circumstance. An impossibility established at the design stage, and accepted in deployment, is a decision — and a decision can be examined.