Column details Lavender AI system and claimed 20-to-1 civilian ratio

Roth, now a Guardian US columnist and senior fellow at Yale University, is the author of “Righting Wrongs: Three Decades on the Front Lines Battling Abusive Governments.” In the column, he argued that the colloquial term “killer robots” — the label for fully autonomous weapons — is deceptive, because the more pressing problem is AI’s growing role in selecting targets for conventional weapons.

Roth reported that for more than a decade, governments have been meeting in Geneva to negotiate limits on autonomous AI weapons. In early September, 128 governments met to approve a report that could serve as the foundation for a binding treaty. According to Roth, lawyers sent by Trump and Putin teamed up to water down the report, particularly weakening a provision that would require humans to review military targets developed by AI before a strike. At stake, Roth wrote, is the longstanding quest to maintain a “human in the loop” — meaningful or effective human control of AI-empowered weaponry.

Roth wrote that for many people, talk of killer robots conjures up images of Arnold Schwarzenegger’s The Terminator, while he himself has often thought about the problem in the context of the Tahrir Square uprising during the Arab Spring that led to the ouster of Egyptian president Hosni Mubarak. Mubarak’s fate was sealed when the Egyptian army made clear it would refuse to fire on Egyptian protesters, Roth wrote, but killer robots would have had no such qualms. “If Mubarak had been able to deploy them, he might have stayed in power,” he wrote.

The negotiators in Geneva, Roth wrote, are not addressing AI weapons used for repression — only those used in war — a limitation he attributed to the Trump and Putin legal teams. “The Trump-Putin lawyers made sure that the agreed report referred only to war, not repression,” he wrote.

Roth turned to ongoing conflicts to illustrate what he described as the present reality of AI in targeting. He wrote that Russian and Ukrainian troops are experimenting with fully autonomous weapons in eastern Ukraine to overcome jamming of drone control signals, and that these deployments are likely to expand.

On Gaza, Roth wrote that the Israeli military is using AI to target Palestinians. He described the “Lavender” system, which Israel deployed after the October 7, 2023 Hamas attack to identify patterns in phone communications equated with Hamas operatives. A separate automated system called “Where’s Daddy?” tracked those individuals to their homes, where they could be more easily targeted. “There was no pretense that Hamas was using its operatives’ homes for military purposes,” Roth wrote. “It was simply easier for the AI system to find suspected Hamas fighters where they slept. The families were the collateral damage.”

Roth acknowledged that the targeting process formally included human review, but described that review as nominal. In the past, Israeli targeting decisions were subject to significant review, he wrote, but in Israel’s killing spree that followed the Hamas attack, the intense demand for targets took precedence over such review. He quoted an Israeli intelligence officer as saying: “I would invest 20 seconds for each target at this stage, and do dozens of them every day. I had zero added-value as a human, apart from being a stamp of approval. It saved a lot of time.” From computer to killing, the human judgment exercised was perfunctory — a “rubber stamp,” according to Roth. “In essence, an algorithm played God,” he wrote.

One Israeli officer suggested the practice might be justified because AI makes better decisions than humans do, Roth wrote. It is dispassionate, while people’s judgment can be clouded, such as by the animosity toward all Palestinians that some Israelis felt after the Hamas attack, the officer said.

Another Israeli soldier, quoted by Roth, expressed greater trust in the AI system than in fellow soldiers: “I have much more trust in a statistical mechanism than a soldier who lost a friend two days ago. Everyone there, including me, lost people on October 7. The machine did it coldly. And that made it easier.”

Roth wrote that AI algorithms are inevitably affected by human input, asking how much evidence is required to identify someone as a Hamas fighter and what margin of error is tolerated. The answer to such questions depends on the judgment of the AI programmers and their commanders — ordinary Israelis who might have devalued Palestinian civilian life in the fury that followed the Hamas attack, he wrote.

Roth noted that the Israeli military conceded that approximately 10 percent of the human targets flagged for assassination were not members of Hamas’s military wing. He also quoted Israeli President Isaac Herzog as saying, in the aftermath of October 7: “It is an entire nation out there that is responsible. It’s not true, this rhetoric about civilians were not aware, not involved – it’s absolutely not true. They could’ve risen up, fought against that evil regime.” That same contempt, Roth wrote, contributed to the Israeli military’s willingness to tolerate civilian deaths.

Roth wrote that the Israeli military permitted an anticipated 20 civilian deaths for the killing of a suspected low-level Hamas fighter. He cited the international humanitarian law principle of proportionality, which prohibits attacks expected to cause civilian casualties “excessive in relation to the concrete and direct military advantage anticipated.” According to Roth, virtually no legal expert considers Israel’s 20-to-one ratio lawful. “These are war crimes,” he wrote. “They reflect an appalling devaluing of Palestinian civilian life.”

In closing, Roth invoked Hannah Arendt’s “banality of evil” to describe what he characterized as ordinary soldiers becoming complicit in extraordinary cruelty by deferring to what they call “the system.” The essence of that system, he wrote, remained people — the generals who ordered its creation, the military lawyers who excused the unjustifiable, the programmers who tweaked the algorithm, the intelligence officers who passed on the computer-generated targets, and the soldiers who launched the attack. He wrote that part of what made it easier to trust the system was the pseudo-scientific precision of AI, and that humans are familiar with the breezy, authoritative tone of today’s chatbots. When AI is used for targeting, Roth wrote, it brings a similar feigned omniscience to killing. “When inevitably flawed human beings make decisions, they can expect others to challenge them,” he wrote. “But AI makes it easier for us to defer to its judgments.” That deference risks magnifying the human biases that inevitably infect any AI system — a pattern the International Committee of the Red Cross calls “automation bias.”

Roth argued that meaningful human control of AI requires not just nominal endorsement of its decisions but intense questioning of its product, along with accountability for commanders when junior officers fall short. “Even in war, people should never be snuffed out by the mechanical application of an algorithm,” he wrote.