GGE’s ‘Rolling Text’: How Will Autonomous Weapons Be Regulated?
by Harry McKenzie
The United Nations (UN) International Youth Day is celebrated every year on 12 August to bring global attention to the voices, actions, and initiatives of young people. In honour of this important day, members of the Stop Killer Robots Youth Network shared their thoughts on the themes of autonomous weapons systems, digital dehumansiation, and youth in disarmament. Disclaimer: The blogs in this series do not necessarily constitute the opinions of Stop Killer Robots, nor should they be considered the opinions and views of all Stop Killer Robots members.
This blog examines the GGE’s rolling text on Lethal Autonomous Weapons Systems (LAWS), outlining its two-tier regulatory structure and analysing how the May 2025 draft differs from the November 2024 version.
As the world becomes ever increasingly machine-dominated, battlefields are no exception. Reports suggest that fully autonomous systems have already been used in conflicts, including in Libya (2020), Ukraine (2023) while artificial intelligence (AI)-enabled decision-support systems (DSS) have reportedly been used by Israel in target generation and identification in Gaza.
AWS (Autonomous Weapons Systems), also referred to as LAWS (Lethal Autonomous Weapons Systems), can be defined as:
“Any weapon system with autonomy in its critical functions — that is, a weapon system that can select (search for, detect, identify, track or select) and attack (use force against, neutralize, damage or destroy) targets without human intervention,” (International Committee of the Red Cross).
To govern these systems, in 2013, State Parties to the Convention on Certain Conventional Weapons (CCW) agreed to a mandate addressing LAWS. In 2016, the CCW formalized discussions with a Group of Governmental Experts (GGE) on LAWS. The GGE has regularly convened since its foundation and has recently published a ‘rolling text’ demonstrating what states agree on to advance work towards a regulatory instrument.
The rolling text lays out a two-tier structure for regulating AWS. This consists of an absolute prohibition on particular types and uses of AWS and then a set of positive obligations and regulations for how all other AWS may be developed, deployed, and operated in compliance with International Humanitarian Law (IHL).
What we might view as Tier 1 is primarily laid out in Section III of the ‘rolling text’ which prohibits “in all circumstances”, the manufacturing, use and stockpiling of AWS that are of a nature to cause “superfluous injury or unnecessary suffering”, those that are “inherently indiscriminate”, and those that are “incapable of being used in compliance with IHL”, for example by contravening the principles of distinction, proportionality and precautions in attack. There are also absolute prohibitions on the use of all types of AWS: they cannot be used to target civilians or civilian objects nor can they be used if their effects cannot be “anticipated and controlled”.
What we might view as Tier 2, a set of positive obligations and restrictions, can be divided into three main and often overlapping areas:
1.) Governance and accountability across the lifecycle
This pillar seeks to assert who is responsible and accountable for the effects of AWS and what standards must be followed to this end. For example, the text calls for legal reviews before deployment, and if any modifications are made (IV.1, IV.4) and emphasises the need for human accountability at all stages of AWS life cycles (V.1-V.4). It proposes ways to achieve human responsibility and accountability by ensuring the understanding of system capabilities and limitations (IV.3) with guidance and training for all personnel (V.5). It also asserts the need for domestic investigation and enforcement mechanisms (V.6-V.7).
2.) Human judgement and control requirements (pre-use)
A primary concern for the use of AWS is the maintenance of human judgement and control, with states disagreeing on the extent to which this should be required. Thus, the text does not assert exactly what such judgement and control should look like throughout AWS life cycles, and instead uses the term “context-dependent”. Nevertheless, the text states that to enable human understanding and judgement, states should conduct “rigorous testing and evaluations” of AWS (IV.5). Moreover, there should be a responsible chain of command, involving the human assessment of legal requirements and ethical considerations regarding the capacities for target selection and engagement (III.6.B). This appears to be context-dependent, with little guidance on what states should not be allowed to do outside of obvious IHL restrictions. The text also states that there should be measures to “detect, correct or mitigate” automation bias (favoring the suggestions of machines) (IV.6). States should also maintain the ability to deactivate AWS in “a timely manner” such as through self-destruction mechanisms (III.6.D.i).
3.) Operational use restrictions
The text also provides requirements for human judgement and control on the autonomy of AWS in mission use. For example, it states that “context-appropriate” human judgement and control must be required for an AWS to modify its mission parameters, such as what it targets, the duration and geographical scope of the mission (III.6.C). Humans should also limit the number of engagements AWS can autonomously undertake, the defined perimeter of an operation and the use of AWS to “objects that are military objectives by nature” and “real time machine-learning” as to target selection and engagement (III.6.D).
This most recent rolling text, published on the 12th May 2025, differs little from its predecessor, published on the 8th November 2024. It consists of some slight language adjustments, such as reframing the need to limit by geographical scope from “avoiding concentrations of civilians or civilian objects” [Nov ’24] to “limiting the operation of LAWS to a defined perimeter in particular to reduce the likelihood of harm to civilians or damage to civilian object” [May ‘25], now no longer precluding the possibility of using AWS in areas with a high concentration of civilians.
Another example is moving from “Ensure that LAWS’ mission parameters cannot be modified by the system without context- appropriate human control and judgement.” [Nov ’24] to “Limiting real-time machine learning with regard to target selection and engagement functions”. This signals a move from a clear-cut avoidance of one of the most dangerous elements of AWS use, real-time adaptation by the system itself, to now merely limiting it. To what extent this limitation would apply remains unclear. AWS real-time adaptation would challenge the notion of “context-appropriate” human control and judgement, potentially leading to civilians being targeted
However, in some areas the May 2025 version uses tighter language. For example, with regards to target selection and engagement functions, the November 2024 text requires that states review “significant changes”, while the May text goes further, requiring review of “any further development or modification” to ensure compliance with IHL.
There is also a shift towards stronger state responsibility across the entire lifecycle of AWS. The May 2025 text affirms that “states undertake not to manufacture, otherwise acquire, stockpile or transfer LAWS that cannot be used in compliance with IHL.” This goes further than the November 2024 text which merely calls on states to determine during the development, acquisition or adoption of a new weapon whether its employment would be prohibited under international law.
A further notable inclusion is the outlining of practical steps that states should take to “promote human accountability and responsibility” in the use of AWS. These include training on the proper use of AWS and the limits of their autonomous functions and “readily understandable human-machine interfaces and controls”. This goes some way towards remedying the lack of a “clear requirement for users to adequately understand a system and its potential effects in the context of use” pointed out by Elizabeth Minor and Richard Moyes of Article 36, though the language used is not as stringent as it would need to be.
Looking ahead, the next draft of the rolling paper will likely hinge on discussions at the September GGE meeting, where states will discuss the opportunities and constraints of the CCW’s consensus-based process. While the current rolling text appears to be moving towards a political framework rather than a legal treaty, Stop Killer Robots continues to advocate for a robust legally binding instrument with clear prohibitions and positive obligations, be this within the CCW framework or through an alternative forum.
Harry McKenzie’s goal is to have as much positive impact on the world as he can. He is a member of the Stop Killer Robots Youth Network and is currently independently researching human levers in AI safety governance. He has previously worked in the political affairs space through his internship with the Labour Middle East Council (LMEC), where he produced weekly MENA briefings for Labour MPs and key stakeholders. His consulting work includes producing research and communications for an African elections campaign. While studying Arabic and Spanish at the University of St Andrews, he created a speaker series attended by over 400 people, engaging diverse public figures from Zoe Cohen of Just Stop Oil to the Saudi Ambassador to the UK. As co-leader of an impactful careers society at St Andrews, he piloted new programs for 60 students focusing on animal welfare activism and AI governance. In his free time, Harry enjoys being disappointed by his favourite football team and cooking.
