Cybergeddon: International Law in the Face of Artificial Intelligence and Cyberattacks

Who is responsible for damage caused by artificial intelligence when the perpetrator acts from outside Poland’s borders? International law has known the answer to this question for decades. The problem is that today it is difficult to enforce.

A Cyberattack Without a Culprit

Let us imagine the following scenario: a power plant in one country falls victim to a cyberattack initiated from outside its territory. The traces lead abroad, but the government of the state from whose territory the perpetrators operated denies everything. There is no international court to which one could immediately turn, and no independent investigator to establish the facts in a binding manner. What can a state, a company, or an individual internet user then do to obtain protection against increasingly effective cybercriminals using sophisticated algorithmic solutions and generative artificial intelligence? In practice, acting on the international legal plane is difficult, if not impossible. Any dispute over the attribution of a cyberattack ends up with politicians, diplomats, and the media, where it is settled not by law, but by geopolitical alliances, persuasive power, and reasons of state.

Rules That Already Exist

Yet the legal rules that should apply directly here have existed for a long time. Customary international law holds that states bear responsibility for damage caused to other subjects of international law, including when they merely allowed their territory to be used to cause such damage. A state is responsible even when it neither ordered nor controlled the harmful act itself, which is particularly important when attributing responsibility for digital operations, given the difficulty of verifying and attributing digital traces. As early as 1949, in the well-known Corfu Channel case, the International Court of Justice held that a state has an obligation not to allow its territory to be used to cause harm to others. These principles of state responsibility apply today also to cyberspace, as confirmed both by the work of the UN Group of Governmental Experts and by the 2024 declaration of the Council of the European Union on the common understanding of international law in cyberspace. International law therefore allows the principles of state responsibility for harmful acts using information technology or artificial intelligence to be defined with relative ease. The problem is the absence of a single institution capable of credibly investigating a specific allegation and issuing a determination that all parties would trust.

The Cost of an Institutional Gap

The absence of such an institution has real consequences. Unconfirmed accusations of a cyberattack are not verified today and are often played out politically. Alliances harden, divisions deepen, and tensions rise regardless of whether a violation of the law occurred. This is a mechanism well known from history: unconfirmed accusations and the absence of a neutral arbiter also escalated tensions a hundred years ago, pushing Europe to the brink of catastrophe. Today, the same dynamic is driven not by a diplomatic dispatch, but by an entry in a server log.

Artificial Intelligence Lowers the Threshold

Artificial intelligence complicates this scenario further by lowering the cost of carrying out a cyberattack or a disinformation campaign, whether sponsored by states or by private actors. Less and less in the way of resources and skills is needed to trigger a serious international incident. This evolution is occurring faster than international institutions are able to respond to it. In other words, the tools used to trigger crises are becoming cheaper, while the mechanisms for resolving them are not increasing in number.

Are We Helpless?

Does this mean that we are helpless? Not necessarily. International law has already encountered similar gaps, clear rules in force alongside inadequate mechanisms for their enforcement, for instance in the protection of seas and oceans or in the law of armed conflict. This occurred before specialized courts and tribunals were established, and over time these gaps were closed through the interpretation of existing norms and principles of international law. The question is how quickly this can be achieved this time, given the pace of development of artificial intelligence and the deepening geopolitical divide.

Trust Instead of Treaties

Before new treaties and tribunals emerge, a distinct role must be played by others: the academic community, non-governmental organizations, the technology sector, and business. These actors can already build independent, multistakeholder mechanisms for verifying events and their circumstances, mechanisms that will not replace future treaty-based solutions but can precede them and feed them with knowledge and practice. These are the actors that can invest in training young experts, so that they are ready to work on effective solutions before the next serious international crisis breaks out. And it is they who can help conduct dialogue between states, business, and academia, building trust where formal institutions are currently lacking.

A Model That Already Works

It is worth emphasizing that this is not an abstract postulate. The multistakeholder model of internet governance, in which decisions concerning network infrastructure are taken jointly by governments, the private sector, the technical community, and civil society, has been functioning for more than two decades, both within the United Nations and beyond it. It has produced real solutions where classical interstate diplomacy proved too slow. This experience can, and should, be transferred to the area of responsibility for cyberattacks. It is precisely this role, building trust and capacity before diplomats and legislators do so, that we wish to examine during this year’s edition of the European Forum for New Ideas in Sopot.

The SSIGIL Report: Twenty-Five Minutes to Midnight

Where do these conclusions come from? They follow, among other things, directly from a report preceded by a week of intensive work by young researchers in international law from five European countries, who met at the Faculty of Law and Administration of the University of Lodz as part of the Summer School on Internet Governance and International Law (SSIGIL). Over five days, they took on the roles of state representatives, confronting realistic scenarios of cross-border cyberattacks of undetermined origin, and jointly attempting to answer the question of who should be responsible for such an attack, and how. The programme was carried out under the EU’s Erasmus+ Blended Intensive Programme, in cooperation with partner universities from Italy, Luxembourg, Lithuania, and Romania.

The result of this work is the report “Twenty-Five Minutes to Midnight: The Accountability Gap”, published by the Centre for International Law in Cyberspace Research “Lodz Cyber Hub” at the Department of International Law and International Relations of the Faculty of Law and Administration of the University of Lodz, edited by Jason Bonsall and dr Joanna Kulesza. The title refers to the Doomsday Clock and makes clear that less than half an hour remains before a digital Armageddon. This is at once a great deal of time, and very little, in which to put in place effective international solutions. The SSIGIL summer school, now in its third edition, strengthens the position of the University of Lodz as one of Europe’s leading centres for training young international lawyers, and the position developed in Lodz will be presented at the December session of the UN Internet Governance Forum (IGF 2026) in Nairobi.

Full SSIGIL26 report  and more information.

 

Dr Joanna Kulesza, University of Lodz

 

 

Main image: SSIGIL Clock, graphic by Renato Di Stefano