Photo by Robynne O on Unsplash.

See all articles

Who Are Legitimate Targets in Modern Armed Conflicts?

Analysing the Status of Tech Company Employees through the Case of Palantir

13.07.2026

On 31 March, the Islamic Revolutionary Guard Corps (IRGC) of Iran declared a list of eighteen American technology companies, including Palantir, Intel, Tesla, Microsoft, and Google, as “legitimate targets”. The IRGC’s asserted rationale was that these firms “actively participate in terrorist designs” and constitute the “main element in designing and tracking assassination targets” within the ongoing armed conflict launched by the USA and Israel on 28 February. The IRGC further advised employees to evacuate immediately and warned residents within a one kilometre radius to seek safety. Notwithstanding the IRGC’s assertion that individual employees may appear to be directly unthreatened at first glance, the association of these companies’ operations with terrorist activities and military operations renders it unrealistic to exclude the individuals carrying out those activities from the scope of the threat.

This threat against technology companies follows the March 1, 2026, Iranian drone strikes on Amazon data centres in the UAE and Bahrain. While Schmitt and Klonowska analysed whether data centres hosting both civilian and military data qualify as dual-use objects and lawful military targets under international humanitarian law (IHL), Iran’s statements raise another critical question regarding the legal status of individuals. Are the employees of these technology companies subject to lawful targeting, or are they protected civilians under IHL?

This post is confined to the legal status of individuals under IHL, using Palantir as a case study due to the comparatively detailed publicly available information regarding its involvement in ongoing hostilities between the USA, Israel and Iran. The analysis, however, applies equally to employees of any other technology company – irrespective of whether they are used by Iran, the United States, Israel, or otherwise – to the extent that their conduct satisfies the three cumulative DPH criteria examined below. The subsequent steps in the targeting analysis, including the assessment of proportionality, and jus ad bellum considerations, are not within the scope of this piece and neither is the territorial scope of targetability; the analysis pertains to employees located in states already party to the conflict.

The Factual Context: Palantir’s Role in the Armed Conflict

To assess the targetability of Palantir’s employees, it is essential to ascertain the extent of the company’s engagement in the present hostilities. Drawing on observations from both Israel’s genocidal war on Gaza and the ongoing conflict between the USA, Israel and Iran, it has been argued that AI companies such as Palantir are not merely “neutral infrastructure providers who happened to find a military customer”; rather they are “defense contractors” directly embedded in conflicts’ “targeting architecture”. Indeed, the company itself states that it was “founded to support critical national security missions” and that its “support for the US military is one of [its] defining commitments”. Its Maven artificial intelligence system, initially engineered for the American drone imagery programme, has become the military’s “primary AI operating system”: on March 2026, Deputy Secretary of Defence confirmed its integration as a “long-term” cornerstone of American military strategy, and a Pentagon’s AI chief has demonstrated how Maven can be used for weapons targeting in the region. Maven’s technology can rapidly analyse voluminous data utilising AI to identify threats or targets. Moreover, the company incorporates additional systems, including Gotham, described by Palantir as the “Operating System for Defence Decision Making” which “enables the autonomous tasking of sensors, from drones to satellites, based on Al driven rules or manual inputs for human-in-the-loop control”.

As reported by NBC News and the Washington Post, quoting unnamed sources, Palantir’s AI systems were “used to identify potential targets” in the Iran case. The CEO confirmed that Claude is used in the Iran war as an embedded programme within Palantir’s systems, but that he cannot discuss details. Concurrently, the head of the USA Central Command confirmed employment in Iran to analyse extensive data in seconds to “make smarter decisions faster than the enemy can react”.

Palantir claims that its Maven software “does not make lethal decisions” and that human still choose and approve the targets. While Palantir asserts this as an indication that decisions rest with military personnel, the company’s Forward Deployed Engineer model traditionally involves civilian employees working closely with clients to deploy and configure its software systems such as Gotham and Maven in operational contexts. Consequently, the strategic inclusion of the company and its employees is becoming increasingly challenging to dismiss in light of Gvaryahu’s observation that such systems are situated within “the kill chain”. Accordingly, a key question raises: Are these employees protected civilians or legitimate targets under IHL?

Are Palantir Employees Directly Participating in Hostilities?

Under the principle of distinction, attacks in armed conflicts are to be directed exclusively at combatants and not at civilians unless and for such time as they take a direct part in hostilities (DPH). Since Palantir’s employees are not members of the armed forces of the USA or Israel, their lawful targetability depends on a single, critical concept: whether their activities amount to DPH.

Despite the well-established status of the DPH rule (in Article 51 of Additional Protocol I and Rule 6 of the ICRC’s 2005 Study on Customary IHL), both treaty and customary law fail to provide a precise definition of “direct participation”. The ICRC’s 2009 Interpretive Guidance, despite not being legally binding, introduced three cumulative criteria, threshold of harm, direct causation, and belligerent nexus, widely applied as a starting point in such assessments and employed to Palantir’s employees below. As DPH functions as an exception to the principle of distinction, entailing the loss of a civilian’s protection, these criteria should be interpreted narrowly (Madhukumar, p. 144).

The first criterion, the threshold of harm, can be met in one of two ways: the act must either result in, or be likely to result in, “adversely affecting the military operations or military capacity” of a belligerent party or “inflicting death, injury or destruction on [protected] persons or objects” (Guidance, p. 47-49). According to the Guidance, the transmission of “tactical targeting information for an attack” would satisfy the criterion as it would result in adverse effects on a party’s military operations (Guidance, p. 48). Therefore, the utilisation of AI systems that have been employed to “sift through vast amounts of data in seconds” to generate and prioritise target lists, enabling kinetic strikes that result in loss of life and widespread destruction, is sufficient to meet this threshold.

The second criterion, direct causation, is one of the most sophisticated and contested aspects of analysing the status of AI company employees. The Guidance necessitates the act to be an integral part of a specific military operation, resulting in harm within “one causal step”. It expressly excludes the acts which “merely build up or maintain the capacity of a party to harm its adversary” such as “scientific research and design, as well as production and transport of weapons and equipment unless carried out as an integral part of a specific military operation designed to directly cause the required threshold of harm” (Guidance, p. 53). Within the collective operations, an act must constitute “an integral part of a concrete and coordinated tactical operation that directly causes such harm”. Furthermore, the Guidance provides several notable examples of acts for the present analysis, including “the identification and marking of targets” and “the analysis and transmission of tactical intelligence to attacking forces” (Guidance, p. 54-55).

This apparently simple formula has become the basis of significant doctrinal debate, particularly where evolving military technologies and weapons are concerned. Schmitt has proposed, in this regard, a test grounded in “the criticality of the act to the direct application of violence against the enemy.” A recent and analogous example arises from the targeting of Iranian nuclear scientists during “Operation Rising Lion”, where Schmitt argued that “the significance of the activity to military operations is the central factor in the assessment of the causality” based on the argument that not every weapon is equal. Accordingly, he contends that nuclear scientists may satisfy the criterion. The majority view, reflected in the Guidance, takes the opposite position: unless such scientists are integrated into a specific military operation, their activities remain confined to merely maintaining the capacity of a belligerent party, and therefore fall outside the scope of direct participation (Dumont/Budelmann; ICRC DPH Report, p. 49). The Guidance’s (p. 53) view is explicit on this point; indispensability alone is insufficient. The risk in adopting a “criticality” or “indispensability” test lies in its potential for self-serving application (Melzer, p. 867-868). Indeed, analogous logic would suggest that any specialist with critical expertise at a technology firm vital to a state’s military success in targeting could be considered lawfully targetable. This would carry significant implications for the principle of distinction, hence, the right to life of the individuals, since a DPH determination renders them liable to targeting; which has potential to increase the already-growing civilian casualties in modern armed conflicts.

Therefore, the interpretation of these provisions needs to be consistent with the object and purpose of IHL and the Geneva Conventions, as articulated by Article 31 of the VCLT. This ensures maintaining a balance between humanitarian consideration and military necessity, with the protection of civilians from direct attacks. As Melzer (p. 868) has warned, failure to do so would result in the practical limits being rendered meaningless, leading to the implementation of “overly broad targeting policies, error, arbitrariness and abuse”. Nevertheless, Schmitt’s assertion that not all weapons serve the same practical purpose remains valid. Consequently, there is a necessity for an interpretation that can adapt to the emergence of new technologies. This post accordingly adopts the more balanced interpretation, retaining the threshold “an integral part of a concrete and coordinated tactical operation” which “directly causes the required threshold of harm” and maintaining that neither all technology company employees nor all Palantir employees satisfy this criterion (Guidance, p. 53-54). Conversely, it would be overly restrictive to categorise every employee of a company supplying critical capabilities to the armed forces of a belligerent party as a protected civilian.

In the context of Palantir, therefore, a distinction is required. The initial category encompasses individuals providing tactical information for integration into specific operations, whose conduct is widely accepted as meeting the direct causation criterion. The subsequent, broader question concerns whether the requisite integration must be tied to a specific individual strike or whether integration into a specific operation linked to the armed conflict suffices. The latter formulation would be more adaptable. Although the internal structure and departmental composition of Palantir is not entirely public, it can be argued that personnel operating within units focused on Iranian persons, objects, or territory may be engaged in acts that “can reasonably be regarded as a preparatory measure integral to a predetermined hostile act or operation” (Melzer, p. 867). Indeed, an excessively restrictive reading would otherwise risk producing the very deficiency Melzer (p. 867) rightly points out in his trainer example, where qualification as direct participation does not depend “on whether the trainer knows precisely when or where that hostile act or operation will be conducted.”

Applied to the present context, for instance, a Palantir software engineer, to the extent that they are involved in operating the Maven or Gotham within the ongoing campaign against Iran, may be engaged in a preparatory measure integral to a predetermined operation, namely the ongoing US targeting campaign, even where the engineer does not know in advance when and which specific strikes will be executed on the basis of the intelligence generated. In contrast, the majority of Palantir’s employees, including an engineer working on Palantir’s general AI infrastructure, data scientists specialising in general intelligence, and human resources personnel, are typically too remote to be considered as DPH. In this capacity, their responsibility is limited to the building the technological architecture; they do not engage directly in tactical military operations. In other words, the acts that they perform are not integrated into any specific operational deployment. Instead, they “merely build up or maintain the capacity of a party to harm its adversary” (Guidance, p. 53), which is insufficient to meet the criterion.

Additionally, the final criterion, the belligerent nexus requires that the “act must be specifically designed to directly cause the required threshold of harm in support [of] a party to the conflict and to the detriment of another” civilian “totally unaware of [their] role” do not meet the criterion (Guidance p. 58, 60). However, as Horowitz (p. 319-320) observed, belligerent parties face a considerable challenge in distinguishing between acts of technology specialist without awareness of the adverse military effects of their conduct and the activities with similar effects but which are specifically designed to support a party and to the detriment of another.

In the context of Palantir, whilst the company’s defence contracts and its CEO’s declarations might demonstrate a belligerent nexus at the corporate level, attributing it to every individual employee would be legally problematic. An employee engaged in the maintenance of civilian healthcare infrastructure via Palantir’s software operates within an entirely different belligerent nexus context.

Conclusion

The preceding analysis demonstrates that the majority of tech employees including those at Palantir are not DPH, therefore safeguarding civilian protection against direct attack under IHL. Nevertheless, a narrower category – those involved in operating systems, including Maven and Gotham, to provide real-time tactical intelligence that is integral to a concrete and coordinated military operations – forfeit their civilian protection, and only “for such time as” they engage in those activities. Whilst the temporal limitation has been criticised as creating a “revolving door” effect, the critical consequences necessitate a defined temporal scope for targetability. Given that technological advancements and the expanding role of technology companies, have already resulted in a shift in the balance in favour of states, particular caution is required when making DPH determinations with such severe consequences as targetability. Similarly, although the post does not focus on military necessity and proportionality, it is important to note that these employees are operating within dual-use facilities used by hundreds of civilians, which would render any such assessment particularly challenging. Otherwise, DPH may be expanded in a manner that places more civilians at risk, contrary to the purpose of IHL and the principle of distinction.

Author
Feyza Gül Keskin Kalyon

Feyza Gül Keskin Kalyon is a PhD candidate at Newcastle University, focusing on the challenges that emerging technologies pose to International Humanitarian Law.

View profile
Print article
3 Comments
  1. Calling Israel’s war “genocidal” as an established fact erases the line between academic analysis and political advocacy. The fact that this passed editorial review should concern not only the author but also the platform that chose to publish it.

    • Thank you for engaging with this article. As outlined on our website, Völkerrechtsblogs is committed to upholding the Code of Conduct for Good Scientific Practice in all our activities, including our peer-review and editorial processes: https://voelkerrechtsblog.org/about/the-blog/

      Should you wish to engage further with the issues raised, we would welcome a scholarly response to the blog post. Submissions may be sent to submissions[at]voelkerrechtsblog.org.

      The Editorial Team

  2. Çalışmalarınızın hayırlara vesile olmasını temenni ediyorum.

Leave a Reply

We very much welcome your engagement with posts via the comment function but you do so as a guest on our platform. Please note that comments are not published instantly but are reviewed by the Editorial Team to help keep our blog a safe place of constructive engagement for everybody. We expect comments to engage with the arguments of the corresponding blog post and to be free of ad hominem remarks. We reserve the right to withhold the publication of abusive or defamatory comments or comments that constitute hate speech, as well as spam and comments without connection to the respective post.

Submit your Contribution
We welcome contributions on all topics relating to international law and international legal thought. Please take our Directions for Authors and/or Guidelines for Reviews into account.You can send us your text, or get in touch with a preliminary inquiry at:
Subscribe to the Blog
Subscribe to stay informed via e-mail about new posts published on Völkerrechtsblog and enter your e-mail address below.