Human rights due diligence — and the military AI debate
Lesson 5 of 5 in AI, Elections, Labor, Competition, and the Planet.
Regulators keep describing AI regimes as "rights-based," and this curriculum keeps invoking fundamental rights — but the machinery underneath comes from a framework most AI professionals have never read: the UN Guiding Principles on Business and Human Rights (UNGPs, endorsed unanimously in 2011). Three pillars: states have a duty to protect human rights; businesses have an independent responsibility to respect them — which exists regardless of whether local law requires it; and victims need access to remedy. The second pillar is operationalised through human rights due diligence (HRDD): an ongoing cycle of identifying, preventing, mitigating, and accounting for human-rights impacts across your operations and your value chain. The UN’s B-Tech project has spent years translating exactly this machinery for technology companies, including a generative-AI harms taxonomy — it is the closest thing to an official answer to "what does respecting rights mean for an AI provider."
Why an AI expert needs this: HRDD is becoming law. The EU’s Corporate Sustainability Due Diligence Directive (CSDDD, 2024) converts the voluntary UNGP cycle into mandatory due diligence for large companies — though verify its current scope and timeline, which the 2025–26 omnibus process delayed and trimmed. And the UNGPs supply the severity logic every serious impact assessment borrows: rank impacts by scale (how grave), scope (how many people), and remediability (can it be undone) — from the rightsholder’s perspective, not the company’s risk register.
That perspective shift is the entire difference between a human rights impact assessment (HRIA) and the assessments you already know. A DPIA asks "what are the risks of this processing to data subjects" within data-protection law; a FRIA asks about fundamental-rights impacts of a specific high-risk deployment. An HRIA runs the full method: scope the system and context, engage affected rightsholders directly (not personas — actual affected people or their legitimate representatives), assess against the full international bill of rights, rank by scale-scope-remediability, act on the findings, track, and publish. The Council of Europe’s HUDERIA is a cousin methodology built for AI specifically — taught in the global domain. In practice you will run these as one integrated assessment with three output views; what the human-rights lens adds is the engagement duty and the insistence that severity is measured on victims, not on corporate exposure.
Pillar 1 — the state duty to protect
States must protect against human-rights abuse by third parties, including business, through policy, regulation, and adjudication. AI translation: this pillar is the justification rights-based AI statutes cite — the EU AI Act’s fundamental-rights architecture and the CoE Framework Convention are Pillar 1 instruments.
Pillar 2 — the corporate responsibility to respect
Independent of local law: a company operating where AI abuse is legal still bears the responsibility. Its operational core is HRDD (identify → prevent/mitigate → track → communicate), covering impacts the company causes, contributes to, or is directly linked to through business relationships — a trichotomy that maps uncannily well onto provider / deployer / value-chain questions in AI.
Pillar 3 — access to remedy
Judicial and non-judicial grievance mechanisms for victims. AI translation: appeal and redress channels for people affected by automated decisions — the least-built pillar in practice, and the first thing a rigorous HRIA flags as missing.
Finally, the domain nearly every AI statute exempts and no AI expert may ignore: military AI. The EU AI Act excludes military and defence uses entirely; national-security carve-outs riddle other regimes. What fills the space is a thin, contested lattice of international humanitarian law (IHL), one national directive, and a decade of diplomacy over lethal autonomous weapon systems (LAWS) — weapons that select and engage targets without further human intervention.
The debate has a stable geometry. The ICRC and a large state bloc want a two-tier treaty: prohibit autonomous weapons that target humans or cannot be used in compliance with IHL; strictly regulate the rest — with the UN Secretary-General calling for a binding instrument. Major military powers — the US, Russia, and others — resist new binding law, arguing existing IHL suffices and definitions are unworkable; the UN’s consensus-bound CCW expert group has produced guiding principles but no treaty in over a decade of talks, which pushed the issue into the UN General Assembly (first LAWS resolutions in 2023 and 2024) and into voluntary tracks: the US-led Political Declaration on Responsible Military Use of AI and Autonomy and the REAIM summit series (The Hague 2023, Seoul 2024). Meanwhile actual practice runs ahead of all of it — loitering munitions with autonomous modes in Ukraine, reported AI-assisted targeting systems in Gaza — a reminder that in this domain, capability is deployed first and governed later, if at all.
| Instrument | Nature | What it actually says | Trap to avoid |
|---|---|---|---|
International humanitarian law | Binding on all parties to conflict | Distinction, proportionality, precaution apply to any weapon, autonomous or not; Art 36 AP I requires legal review of new weapons | Binding, yes — but written for human decisions; how it constrains machine speed and scale is the whole dispute |
DoD Directive 3000.09 (2012, updated 2023) | Binding US internal policy | Autonomous and semi-autonomous weapons must allow appropriate levels of human judgment over the use of force; certain systems need senior-official review before development and again before fielding | It is not a ban and does not require a “human in the loop” for every engagement — “appropriate human judgment” is a deliberately flexible standard set at design and authorisation, not per shot |
CCW GGE on LAWS | Treaty forum, consensus-bound | 11 guiding principles (2019): IHL applies, human responsibility retained, accountability non-transferable to machines | A decade of talks, no treaty — consensus rules give every military power a veto; do not cite the GGE as if it produced binding limits |
UNGA resolutions (2023, 2024) | Non-binding, majority-voted | Put LAWS on the General Assembly agenda, commissioned the Secretary-General’s report, built pressure for a binding instrument | Momentum markers, not law — but they broke the CCW’s monopoly on the issue |
Political Declaration + REAIM | Voluntary political commitments | Responsible-use norms: human accountability, testing, auditability of military AI; dozens of endorsing states | Endorsement lists are diplomatic signals; several endorsers deploy the very systems under debate |
Key terms: ungps, human rights due diligence, hria, csddd, lethal autonomous weapons, meaningful human control
Tool: Global Governance Atlas — Open the Governance Atlas and trace how the topics in this module — elections, labor, competition, environment, military — attach to different institutions in each jurisdiction.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.