The emergence of AI‑driven targeting platforms marks a profound shift in how modern militaries identify and engage adversaries. Systems such as Israel’s Lavender ingest massive streams of surveillance data—satellite imagery, mobile phone pings, video feeds, financial transactions, and social‑network maps—to generate a risk score for every individual in a conflict zone. This score is intended to estimate the likelihood of affiliation with militant groups, turning an entire population into a ranked list of potential targets. By automating the early stages of the kill‑chain, the technology compresses decision‑making from hours or days into seconds, promising speed and efficiency. However, this acceleration comes at a steep cost: the very design of the scoring model treats civilian presence as a background variable rather than a protected category, embedding the risk of indiscriminate harm into the algorithm’s core logic.
Delving into the mechanics of Lavender reveals a reliance on positive‑unlabeled learning, a semi‑supervised technique that builds profiles from a small set of confirmed combatants and then scores the rest of the population by similarity. The heterogeneous data sources—ranging from drone footage to payment histories—are fused into a unified dataset estimated at over 13 petabytes. A statistical “likeness” score between 1 and 100 is then assigned to each person, and a configurable threshold determines who becomes a target. Because the model is trained on limited, possibly biased examples of militants, it inevitably flags many civilians whose behavioral patterns—such as frequent movement, communication with certain contacts, or residence in dense neighborhoods—mirror those of the training set. The resulting false‑positive rate, acknowledged in internal tests to be around ten percent, translates into thousands of non‑combatants being earmarked for attack before any human review occurs.
Parallel to Lavender, the Israeli military employs a companion system known as “The Gospel” to classify buildings and infrastructure. Using the same data fusion pipeline, The Gospel assigns each structure a probability of military use, guiding decisions about which sites to strike. While less publicly detailed, the system operates on analogous principles: it treats civilian objects as latent variables that can be re‑classified as legitimate targets based on patterns of activity, occupancy, or proximity to suspected fighters. When combined, Lavender and The Gospel create a end‑to‑end targeting workflow where human analysts receive a batch of person‑and‑location pairs, each already scored for lethality and collateral risk. The integration of these tools exemplifies how AI is not merely an advisory aid but a structural component of the targeting process, shaping which lives and properties are deemed expendable before a commander ever signs off.
The sheer volume of outputs produced by these systems underscores their systemic nature. Analysts estimate that Lavender generated roughly one thousand potential human targets per day during the initial two years of the Gaza‑Lebanon conflict, culminating in over 850 000 scored individuals by the end of 2025. Given Gaza’s population of approximately two million, this means that nearly half of the inhabitants were repeatedly placed on a kill‑list, often multiple times as thresholds were adjusted to match available munitions and aircraft. The dynamic thresholding—lowered when idle bombers awaited new assignments—demonstrates that the system’s outputs are not driven by intelligence quality but by the military’s capacity to deliver violence. Consequently, the targeting process becomes a self‑fulfilling loop: more weapons available lead to lower thresholds, which produce more targets, which justify further weapon deployment.
Human oversight, nominally present in the workflow, is severely compromised by time pressure and automation bias. Reports indicate that analysts spend no more than twenty seconds per target, often limiting their check to verifying the subject’s gender. This perfunctory review fails to satisfy the substantive requirements of international humanitarian law, which demand a rigorous assessment of distinction, proportionality, and precaution. The phenomenon of automation bias—where operators over‑rely on algorithmic outputs—further erodes any meaningful scrutiny, turning human reviewers into rubber stamps. In effect, the safeguards meant to prevent unlawful attacks are hollowed out, allowing the AI‑generated list to translate directly into strikes without adequate verification of civilian presence or military necessity.
The configuration of acceptable collateral damage reveals an explicit tolerance for civilian casualties embedded within the targeting software. Internal documentation cited by investigators shows that for lower‑scoring suspects the system was preset to allow fifteen to twenty civilian deaths per strike, while higher‑scoring individuals could entail “hundreds” of projected non‑combatant losses. When extrapolated across the daily target load, this implies a baseline expectation of thousands of civilian casualties per week. Moreover, operational patterns show a preference for nighttime strikes—dubbed “Where’s daddy?”—when families are more likely to be home together, amplifying the human cost. Such pre‑set harm thresholds are not accidental side effects; they are deliberate parameters that treat civilian loss as a calculable cost of doing business, directly contravening the principle of proportionality that forbids excessive incidental damage relative to the anticipated military advantage.
The technological backbone enabling this scale of surveillance and scoring is a consortium of major cloud and IT vendors. Google and Amazon provide the storage and compute resources under Project Nimbus, a contract valued at 1.2 billion US dollars, housing the petabyte‑scale Gaza dataset. Data integration across disparate feeds is handled by Palantir, while Microsoft, Cisco, Dell, and Red Hat/IBM supply networking, security, and system‑management layers. This private‑sector involvement illustrates how commercial cloud infrastructure, artificial‑intelligence tooling, and enterprise‑software expertise are being repurposed for military targeting. The reliance on these vendors raises questions about due diligence, end‑use monitoring, and the extent to which corporations can claim ignorance of how their products facilitate potential violations of humanitarian law.
From a legal standpoint, the scholars who analyzed Lavender conclude that the system’s design constitutes a systematic breach of international humanitarian law. The core IHL principles—distinction between combatants and civilians, proportionality of attacks, and the obligation to take feasible precautions—are not merely violated in isolated incidents; they are undermined by the very architecture of the targeting pipeline. Because civilian harm is pre‑programmed through scoring models, configurable collateral thresholds, and threshold adjustments tied to weapon availability, the harm is not an aberrant malfunction but an anticipated outcome. This systematic character means that invoking defenses such as “fog of war” or “human error” is insufficient; the unlawful results are embedded in the algorithmic logic and operational procedures that produce them.
Assessing whether the Lavender framework could be reformed to comply with legal standards leads to a sobering conclusion: meaningful adaptation is practically unfeasible. Setting the permissible civilian‑death parameter to zero would strip the model of its ability to differentiate between militants and non‑combatants in an densely populated urban environment, likely yielding zero viable targets and rendering the system useless for its intended purpose. Moreover, the underlying scoring mechanism inherently conflates behavioral similarity with militant affiliation, a proxy that cannot be refined without access to ground‑truth labeling that is ethically and logistically impossible to obtain at scale. Consequently, any attempt to salvage the system while preserving its core function would either perpetuate unlawful harm or negate its utility, indicating that the technology, as conceived, is incompatible with the demands of international law.
The Lavender case is not an isolated phenomenon; similar AI‑assisted targeting practices have surfaced in other theaters, pointing to a broader trend of algorithmic warfare that strains humanitarian protections. Reports from Iran, for instance, describe the use of machine‑learning models to sift through communications and satellite data to identify alleged insurgent sites, resulting in strikes on civilian infrastructure such as schools. These instances share common traits: reliance on opaque probabilistic scoring, minimal human review, and configurable harm thresholds that prioritize operational tempo over civilian safety. The diffusion of such capabilities is facilitated by the global market for dual‑use AI tools, where commercial analytics platforms are readily adapted for military ends, often with limited oversight from exporting states.
Addressing these challenges requires a multifaceted response grounded in accountability, transparency, and proactive regulation. International courts, including the International Criminal Court, have begun to scrutinize AI‑enabled targeting as potential evidence of war crimes, while states may invoke universal jurisdiction to prosecute offenders regardless of where the acts occurred. Export controls on AI‑targeting software must be strengthened, treating such systems akin to munitions that facilitate serious violations of humanitarian law. Additionally, governments and defense contractors should be compelled to disclose the design, training data, and operational parameters of targeting algorithms, enabling independent audits for compliance with distinction and proportionality norms. Civil society and technical communities can contribute by developing open‑source tools that model the impact of scoring thresholds on civilian populations, thereby informing policy debates.
For stakeholders navigating this evolving landscape—policymakers, technology firms, investors, and advocacy groups—several actionable steps emerge. Policymakers should prioritize the enactment of legally binding norms that prohibit the deployment of targeting systems which preset civilian harm thresholds or lack verifiable discrimination mechanisms. Technology companies must conduct rigorous human‑rights impact assessments before entering defense contracts, implement mechanisms for end‑use monitoring, and be prepared to withdraw support when misuse is detected. Investors ought to scrutinize defense‑technology portfolios for exposure to AI‑targeting assets that carry significant legal and reputational risk, favoring firms with robust compliance frameworks. Finally, advocacy groups should continue to document and publicize cases where algorithmic targeting results in civilian harm, using evidence to push for treaty‑level reforms that clearly delineate the limits of automation in warfare. By combining legal pressure, market incentives, and technical transparency, the international community can work toward ensuring that AI serves to protect, rather than endanger, civilian populations in conflict zones.