The Governance Problem
The regulatory and humanitarian regimes that now govern autonomy in weapon systems do not ask whether a system can identify and engage a target. They ask whether the decision to engage can be reconstructed: what confidence supported it, against which dimensions, under whose authorization, and whether the conditions that justified it still held at the moment of action. DoDD 3000.09 requires that commanders and operators exercise appropriate levels of human judgment over the use of force, and that the system's design make that judgment auditable. Article 36 legal review requires that a state party be able to establish, in advance and on the record, that a new means or method of warfare can be employed consistent with international humanitarian law. The CCW GGE on LAWS and the ICRC ethical position both press toward predictability, accountability, and meaningful human control as structural properties, not as documentation produced after the fact.
A conventional autonomy stack cannot satisfy these regimes because it collapses a multi-dimensional legal judgment into a single fire-control gate. Target identification confidence, rules-of-engagement compliance, collateral-damage assessment, and chain-of-command authorization are distinct legal questions with distinct evidence, yet a stateless inference engine fuses them into one score and retains no record of how that score was assembled. Authorization, once granted, persists until the engagement completes, even when the target's behavior or the surrounding environment changes the proportionality calculus mid-engagement. And the human in the loop is authenticated by a static credential that says nothing about whether the operator was impaired, substituted, or coerced. Each of these is a structural deficiency, and each maps directly to a capability the disclosed embodiment supplies.
Graduated Confidence-Governed Escalation
The integrated defense embodiment instantiates the confidence governor of Chapter 5 as an escalation authorization mechanism with multiple confidence thresholds governing progressively consequential actions. At a first threshold the system is authorized to observe and classify a detected entity. At a second threshold it is authorized to issue a warning. At a third threshold it is authorized to recommend engagement to a human operator. At a fourth threshold, applicable only in systems where autonomous engagement is legally and operationally authorized, it is authorized to execute engagement. Each successive threshold requires progressively higher confidence, so that the consequentiality of an action and the evidentiary burden to authorize it rise together.
The confidence at each threshold is not a monolithic number. It is computed from structured inputs comprising target identification confidence, rules-of-engagement compliance confidence, collateral damage assessment confidence, and chain-of-command authorization confidence. Decomposing authorization along these dimensions is precisely what Article 36 review and DoDD 3000.09 demand: each is a separable legal question, each can be evaluated against its own evidence, and each is recorded independently. The confidence computation at every threshold is deterministically recorded in the system's lineage, producing a complete accountability chain from sensor data through confidence evaluation through escalation decision. Because the authorization gate is implemented as a structural decoupling of the execution subsystem's output pathway rather than as a flag the execution subsystem may check and optionally respect, the prohibition below threshold is enforced at the architectural level: the system cannot commit an engagement regardless of the urgency of its internal intent.
Referring to the graduated escalation architecture, an Observation Threshold feeds a Warning Threshold upon sufficient confidence, the Warning Threshold feeds an Engagement Threshold, the Engagement Threshold feeds a Quorum Gate, the Quorum Gate feeds Continuous Re-evaluation, and Continuous Re-evaluation feeds Rules of Engagement, which supplies the policy constraints that govern every threshold evaluation and engagement action throughout the pipeline.
Integrity-Tracked Rules-of-Engagement Compliance
The integrity engine of Chapter 3 is instantiated to track compliance with rules of engagement and international humanitarian law as a continuously maintained dimension of the system's behavioral state, not as a one-time pre-engagement check. The integrity field monitors adherence to the four cardinal constraints of the law of armed conflict: proportionality, distinction, necessity, and precaution. Each engagement event is evaluated against the applicable rules of engagement, and any deviation is recorded as an integrity deviation with full semantic context. The redemption engine then generates restorative actions: recalibration of targeting parameters, restriction of engagement authorization, and submission of the deviation event to the chain-of-command accountability system.
The consequence is that compliance is cumulative and self-restricting. A system that accumulates engagement deviations experiences progressively restricted engagement authorization through the integrity-to-confidence pathway, because the integrity engine's assessment feeds the confidence governor that gates escalation. A platform that has drifted from its rules-of-engagement profile cannot simply re-clear the engagement threshold on the next target; its degraded integrity state lowers its computed authorization confidence until the deviations are addressed.
Continuous Re-Evaluation and Revocable Authorization
Authorization in this embodiment is a revocable permission, not a one-time gate. The confidence governor operates continuously during engagement, not merely at the authorization point. Once engagement is authorized and initiated, the governor re-evaluates confidence at each computational cycle against updated sensor data, environmental changes, and target behavior changes. If confidence drops below a re-evaluation threshold during engagement, because the target's behavior changes, because environmental conditions alter the collateral-damage assessment, or because new information becomes available, the governor revokes engagement authorization during execution, producing an engagement interruption that returns the system to the observation state. Authorization obtained at one moment does not persist if the conditions that supported it change. This directly answers the proportionality and precaution obligations of the law of armed conflict, which are continuing duties rather than instantaneous ones.
The structural separation of execution from cognition makes revocation safe: suspending execution does not suspend cognition. A system whose engagement authorization has been withdrawn retains full access to its forecasting, planning, inquiry, and self-assessment faculties, so it can re-acquire situational understanding and re-authorize only when confidence recovers above the threshold by a configurable hysteresis margin, preventing oscillation near the boundary.
Forecasting and Operator Authentication
Two further primitives complete the embodiment. The forecasting engine of Chapter 4 is instantiated to generate and evaluate engagement alternatives as a planning graph: a primary engagement approach, alternative approaches with different risk and collateral profiles, and non-engagement alternatives including continued observation, warning escalation, and tactical withdrawal. The integrity engine prunes branches whose projected consequences violate rules of engagement, so an approach with projected collateral damage exceeding the proportionality threshold is removed before it can be promoted to execution. The moral trajectory forecasting module projects the consequences of each branch across immediate tactical, near-term operational, and longer-term strategic and humanitarian horizons.
The biological-identity architecture of Chapter 9 authenticates operators through behavioral continuity rather than static credentials. Defense operators are authenticated through continuous behavioral signals, command input dynamics, interaction patterns, and behavioral consistency, rather than through credentials that could be compromised or transferred. The biological-identity module detects operator impairment through changes in behavioral signal dynamics and, on detecting impairment, triggers the confidence governor to restrict the system's autonomous authority and require additional chain-of-command authorization. Authentication thus becomes a live property of the human channel in the quorum rather than a one-time login.
Deployment Variations
The embodiment is parameterized rather than rebuilt across deployments, and several configuration axes are available to an implementer. The escalation ladder can be configured with the fourth, autonomous-engagement threshold disabled entirely, yielding a recommend-only system that never executes engagement without a human commit, for theaters or platforms where autonomous engagement is not legally authorized. The per-dimension weighting of target identification, rules-of-engagement compliance, collateral-damage assessment, and chain-of-command authorization confidence can be tuned to the platform and mission, raising the evidentiary burden on distinction in dense civilian environments or on proportionality where collateral risk dominates. The quorum channel set can be extended beyond the baseline three, adding coalition-authority or legal-review channels, with the lethal-engagement rule that any single veto prohibits the action preserved across the extended set. The rules-of-engagement policy that constrains every threshold is supplied as configuration, so the same architecture serves different theaters, mission profiles, and coalition agreements by policy change rather than by code change. Across all of these variations the invariant properties hold: graduated thresholds, decomposed and recorded confidence, non-shared-state quorum, revocable authorization under continuous re-evaluation, and complete lineage of every confidence computation and engagement decision for post-action accountability.
Disclosure Scope
The defense and national-security engagement-authorization embodiment, comprising the confidence governor instantiated as a graduated escalation mechanism with observation, warning, engagement-recommendation, and engagement-execution thresholds each requiring progressively higher confidence computed from target identification, rules-of-engagement compliance, collateral-damage assessment, and chain-of-command authorization dimensions; the integrity engine instantiated as a continuously tracked rules-of-engagement and international-humanitarian-law compliance monitor across proportionality, distinction, necessity, and precaution, with redemption-generated restorative actions and the integrity-to-confidence pathway that progressively restricts authorization after accumulated deviations; quorum-based engagement authorization requiring independent, non-shared-state confirmation from the confidence governor, integrity engine, and chain-of-command channel, maximally strict for lethal engagement with any single veto producing unconditional prohibition; continuous re-evaluation during engagement producing revocable authorization with the structural separation of execution from cognition; integrity-constrained planning-graph generation with moral trajectory forecasting; biological-identity operator authentication with impairment detection; and complete lineage recording of every confidence computation and engagement decision for post-action accountability, is disclosed in United States Patent Application 19/647,395 in Section 13.2, drawing on the confidence governor of Chapter 5, the integrity engine, redemption engine, and integrity-weighted quorum governance of Chapter 3, the forecasting engine and moral trajectory forecasting of Chapter 4, and the biological-identity architecture of Chapter 9. This article describes that disclosed mechanism and introduces no scoring, parameter, or benchmark machinery beyond what the filing recites. The scope contemplates use only in systems where autonomous engagement is legally and operationally authorized, and extends to the theaters, mission profiles, platform types, and coalition arrangements that the disclosed primitives accommodate through domain-specific policy, threshold, and governance configuration, the defense system instantiating the same platform primitives that operate across the other application domains rather than a separately developed subsystem.