The integration of artificial intelligence into military targeting has moved from experimental prototypes to operational systems that shape real‑time combat decisions. The Lavender system, employed by the Israeli Defense Forces, illustrates how vast data streams—ranging from satellite imagery to mobile phone metadata—are fused to generate a risk score for every individual in a contested area. This score, presented as a number between 1 and 100, is intended to estimate the likelihood that a person is affiliated with a militant group. By converting complex behavioral patterns into a single metric, Lavender compresses intricate sociotechnical realities into a format that can be rapidly consumed by commanders and weapon platforms.
Under the hood, Lavender relies on a machine‑learning technique known as Positive Unlabeled Learning (PUL). A limited set of confirmed combatant examples serves as the positive label, while the massive pool of unlabeled data—civilians, infrastructure, ambient signals—is statistically compared to those examples. The algorithm computes a similarity score that is then rescaled into the 1‑100 risk value. This approach inherently assumes that any deviation from the known combatant profile is suspicious, a premise that blurs the line between combatant and non‑combatant in densely populated urban environments where behavioral patterns overlap considerably.
Complementing Lavender, the Gospel system focuses on the built environment, classifying structures as civilian, commercial, or military based on the same heterogeneous data feeds. By assigning a probable use to buildings, Gospel feeds target recommendations to the kill‑chain, suggesting which structures should be struck to disrupt enemy capabilities. Together, Lavender and Gospel create a closed loop: personnel scores guide the selection of human targets, while building scores dictate the munitions and tactics employed, producing a highly automated targeting pipeline that leaves little room for deliberative human judgment.
The scale of this automation is staggering. Analysts estimate that during the first two years of the recent Gaza‑Lebanon confrontation, the system produced roughly 1,000 candidate targets each day, amounting to over 850,000 distinct entries logged by the defense contractor Elbit Systems. These figures suggest that upwards of half of Gaza’s population and its infrastructure were placed onto a targeting list at some point. Because the threshold for inclusion is adjusted dynamically—lowered when surplus munitions or aircraft are available—the process appears driven more by available firepower than by a fixed evidentiary standard, raising serious concerns about the arbitrariness of the kill list.
Human oversight, while formally present, is severely constrained. Reports indicate that each target receives at most twenty seconds of review by a human operator, who often checks only whether the target is male before approving the strike. This fleeting examination exemplifies automation bias, where operators place undue trust in algorithmic outputs and neglect critical scrutiny. When life‑and‑death decisions are compressed into such brief windows, the procedural safeguards mandated by international humanitarian law—distinction, proportionality, and precaution—become virtually impossible to uphold in practice.
The system’s design explicitly tolerates, and in some cases anticipates, substantial civilian harm. Internal testing revealed an error rate of about ten percent, meaning that roughly one in ten individuals flagged as a combatant may be a non‑combatant. Moreover, the rules of engagement embedded within Lavender permit preset collateral damage thresholds: for lower‑scoring targets, up to twenty civilian casualties may be deemed acceptable, while for high‑value individuals the allowance can rise into the hundreds. Strikes are frequently scheduled for nighttime when families are together, a tactic informally dubbed “Where’s daddy?” that exacerbates the toll on non‑combatants and reveals a calculated acceptance of civilian loss as a feature rather than a bug.
From a legal standpoint, Lavender’s operation appears to violate the three core principles of international humanitarian law. The principle of distinction requires combatants to be distinguished from civilians; Lavender’s probabilistic scoring fails to provide reliable discrimination. Proportionality demands that anticipated civilian harm not be excessive relative to the concrete military advantage; the pre‑authorized casualty allowances suggest a predetermined excess. Finally, the precaution principle obliges parties to take all feasible steps to minimize civilian harm; the system’s configuration, speed, and limited human review indicate a systematic omission of such steps. Consequently, civilian casualties are not incidental mistakes but an inherent outcome of the algorithmic design.
The term “systematic” is apt because the harm emerges from the architecture itself, not from isolated glitches. The deterministic steps—data ingestion, similarity scoring, threshold setting, and automated recommendation—produce a predictable pattern of over‑targeting that scales with the volume of data and the system processes. Internal documents show that operators were instructed to adjust the risk threshold to meet daily strike quotas, confirming that the scale of violence was a policy choice enabled by the technology, not an unavoidable side effect. This repeatable, policy‑driven outcome underscores that the technology functions as a force multiplier for a strategy that accepts large‑scale civilian loss as permissible.
Underpinning this capability is a massive technical infrastructure. The consolidated data set for Gaza is estimated at 13.6 petabytes, stored and processed via cloud services supplied by Google and Amazon under the Nimbus project, a contract reportedly worth 1.2 billion USD. Data integration and analytics are performed by Palantir, while Microsoft, Cisco, Dell, and Red Hat/IBM provide ancillary IT support, illustrating how a consortium of private‑sector firms enables the military kill‑chain. This public‑private coupling means that advancements in commercial AI and cloud computing are rapidly repurposed for lethal targeting, blurring the boundary between civilian technology markets and defense procurement.
Evidence suggests that the Lavender model is not an isolated case. Similar AI‑assisted targeting frameworks have surfaced in other theaters, including alleged U.S. operations in Iran where algorithmic strike recommendations were applied to outdated intelligence, compounding risks to civilians. These parallel developments indicate a emerging norm in which probabilistic targeting tools are deployed to accelerate kill‑chains, often outpacing the capacity for legal review and humanitarian oversight. As more states acquire or develop such systems, the potential for widespread erosion of IHL standards grows, prompting urgent scrutiny from international bodies and human‑rights watchdogs.
Addressing these challenges requires a multi‑layered response. First, systems like Lavender that embed foreseeable civilian harm into their operational logic should be suspended pending rigorous legal and technical review. Second, transparency must be mandated: governments and contractors should disclose the data sources, model architectures, and decision thresholds used in targeting algorithms. Third, export controls ought to be extended to AI‑enabled targeting software, treating it akin to other dual‑use munitions to prevent proliferation to actors with questionable human‑rights records. Fourth, accountability mechanisms—ranging from national prosecutions to investigations before the International Criminal Court—must explicitly consider the role of algorithmic decision‑making in assessing culpability for violations of IHL.
For policymakers, the lesson is clear: procurement guidelines for defense AI must incorporate explicit IHL compliance checks, independent audits, and sunset clauses that trigger review after a defined operational period. Technology companies should adopt ethical AI frameworks that prohibit the facilitation of mass civilian harm, conduct human‑rights impact assessments, and consider licencing restrictions that prohibit use in contexts where distinction and proportionality cannot be guaranteed. Investors and shareholders need to demand transparency about defense‑related AI exposure and encourage divestment from ventures that contribute to unlawful harm. Civil society and academia must continue to document, analyze, and publicize the effects of such systems, providing the evidence base necessary for normative and legal change. Only through coordinated action across these spheres can the promise of AI be harnessed without sacrificing the fundamental protections that underlie humanitarian law.