When Old Laws Meet New Weapons: The San Remo and Tallinn Manuals
The Eternal Challenge: Law Chasing Technology
There's a peculiar problem that haunts international law: by the time we codify the rules, the battlefield has already transformed. This tension lies at the heart of two remarkable documents—the San Remo Manual on naval warfare (1994) and the Tallinn Manual on cyber operations (2013)—which represent humanity's repeated attempt to impose legal order on the chaos of conflict in domains the Framers of international law never contemplated.
Both manuals tell the same story, though separated by technology and domain: we inherited a legal framework designed for armies marching across fields and warships firing broadsides, and we're desperately trying to make it work for submarines, missiles, and now, lines of code.
The San Remo Manual: Modernizing an Ancient Sea
When the International Institute of Humanitarian Law adopted the San Remo Manual in June 1994, it was addressing a genuine legal vacuum. Since 1913, when naval warfare was last comprehensively codified, the ocean had undergone a revolution. Submarines had shifted from novelties to core naval strategy. Aircraft carriers had replaced battleships. Missiles could strike from hundreds of kilometers away. Yet international law remained tethered to doctrines written when engagements involved cannons and line-of-sight combat.
The San Remo Manual did something deceptively simple: it declared that existing international humanitarian law applied to naval warfare. It took the Geneva Conventions, Protocol I, and established customary law, then carefully worked through how each principle translated to the sea. The result was over 200 rules covering everything from targeting restrictions to protections for medical vessels to the legal status of submarines.
What's remarkable is how unremarkable this seems. The legal principles themselves weren't new—distinction between combatants and civilians, proportionality in attacks, protection of neutral shipping. But applying them to naval warfare required sophisticated legal reasoning. How do you determine a submarine's status when its flag is hidden? At what point does a blockade become collective punishment of civilians? When does a merchant ship become a legitimate military target?
The San Remo Manual became a reference point precisely because nations had no other agreed framework. When Israel faced international criticism over the 2010 Gaza flotilla incident, both sides cited San Remo. It provided the language for debate, even among those who disagreed on application.
The Tallinn Manual: When Law Meets Code
A quarter-century later, the international legal community faced an eerily similar crisis. Cyber operations were becoming central to national security strategies, yet international law was virtually silent on the subject. Were cyber attacks covered by laws on armed conflict? Could a cyber operation constitute an "armed attack" triggering a right to self-defense? Could hackers be combatants? What about civilian infrastructure like power grids and hospitals?
Between 2009 and 2012, roughly twenty international legal scholars and cyberwarfare experts convened in Tallinn, Estonia, to answer these questions. Their work resulted in the original Tallinn Manual (2013), followed by the more expansive Tallinn 2.0 (2017), addressing not just warfare but broader cyber operations, espionage, and intellectual property theft.
The Tallinn Manual made a critical assertion: international law—the same law governing traditional armed conflict—applies to cyber operations. A cyber attack that destroys a power plant's control systems might constitute an armed attack. Cyber espionage might violate sovereignty principles. Disproportionate attacks on civilian networks might violate humanitarian law. But—and here's where it gets thorny—existing law wasn't written for a domain where:
- Attribution is nearly impossible
- A weapon fires instantly across the globe
- Civilian infrastructure is intertwined with military systems
- Damage can be temporary, persistent, or reversible
- Intent can be ambiguous (is this espionage? An experiment? A preparation for attack?)
The Parallel Problem: Applying Yesterday's Law to Tomorrow's Warfare
Here's where San Remo and Tallinn reveal something profound: the challenge isn't that we need new laws; it's that we're trying to fit genuinely new problems into old conceptual categories.
Take the principle of distinction—perhaps the cornerstone of modern humanitarian law. The rule is elegant: you must distinguish between combatants and civilians, and you cannot intentionally target civilians. On land and sea, this is hard but comprehensible. A soldier in a uniform is a combatant. A civilian in a hospital is protected.
But in cyber? What is a "combatant"? Is a civilian hacker working for the military a combatant? What about a private cybersecurity contractor hired by the government? And how do you distinguish between a military server and a civilian one when critical infrastructure—hospitals, water systems, power grids—relies on connected networks that could have military users?
The San Remo Manual navigates this by importing legal concepts developed for surface ships: examining a vessel's design, armament, and military crew. But submarines create gray zones. A submarine could be military, smuggling weapons, or civilian. The manual says you must consider the circumstances, but that's not a bright-line rule—it's an invitation to interpretation.
The Tallinn Manual faces even murkier territory. It maintains that cyber operations follow the same rules as conventional warfare, but what happens when a cyber attack causes economic damage worth billions but no deaths? Traditional law expects that massive economic harm might justify self-defense. But if a cyber operation against financial systems doesn't destroy physical infrastructure, is it an "armed attack"? The manual's answer—that it could be, depending on its effects—leaves states to make judgment calls.
The Question They Can't Quite Answer
Both manuals share an uncomfortable silence: they assume that traditional international law's categories are sufficient, but they reveal, through their complexity, that these categories might not be.
The San Remo Manual works because naval warfare, despite its technological evolution, still involves ships moving through space and weapons with visible effects. The legal framework of force, consequence, and attribution—however stretched—still applies.
But cyber operations challenge this more fundamentally. A sophisticated cyber attack is closer to espionage than to warfare, yet espionage is typically legal under international law. A destructive cyber operation is closer to sabotage than to an "armed attack," yet the damage can equal airstrikes. Attribution to a state can be uncertain, yet international law assumes we know who's attacking whom.
What These Manuals Actually Tell Us
Yet dismissing San Remo and Tallinn as inadequate would miss their true significance. Both documents are less about providing definitive answers and more about establishing the principle that international law applies everywhere. They represent the claim that even in new domains, nations cannot act without legal constraint.
The San Remo Manual asserts: Naval warfare is not a lawless realm; existing humanitarian law governs at sea. This seemingly modest claim was revolutionary because it created a framework for international debate. States cite San Remo not because it perfectly resolves disputes, but because it gives them a shared vocabulary for discussing maritime conflict.
The Tallinn Manual makes a similar move: Cyber operations are not exempt from international law. This is important not because every nation agrees on application, but because it establishes that cyber warfare, like naval warfare, is subject to legal norms.
The Deeper Insight: Law as Framework, Not Algorithm
Perhaps the real lesson is that international humanitarian law was never designed to be a algorithm—a set of rules you plug into a computer to generate the right answer. Instead, it's a framework for reasoning about complex situations.
Both manuals work by:
- Asserting continuity: New domains are governed by existing principles (distinction, proportionality, necessity)
- Acknowledging complexity: Explaining how traditional rules apply in non-traditional contexts
- Enabling interpretation: Providing detailed commentary that allows states and courts to adapt principles to specific situations
This approach has strengths and weaknesses. It prevents the chaos of lawlessness—everyone agrees international law applies. But it also leaves ambiguity—reasonable people disagree on how law applies.
Looking Forward: Are These Manuals Enough?
As cyber capabilities evolve at breakneck speed, and as new technologies (autonomous weapons, AI-assisted targeting, space-based systems) emerge, we face the same question again. Will the Tallinn Manual's application of traditional humanitarian law to cyber operations remain adequate? Or will we soon need a Tallinn 4.0, 5.0, and beyond?
The San Remo Manual's 30-year tenure suggests that well-reasoned manuals can remain relevant longer than expected, particularly when they're framed as principles rather than rigid rules. But it also shows that new technologies create new questions that manuals weren't written to answer.
The deeper question might not be whether San Remo and Tallinn are adequate, but whether international humanitarian law itself—designed for a world of nation-states with uniforms, territories, and visible weapons—can accommodate a world of private hackers, proxy forces, hybrid warfare, and attacks that blur the line between military action and crime.
Conclusion: The Eternal Game of Legal Catch-Up
What San Remo and Tallinn remind us is that international law doesn't prevent conflict—it simply tries to regulate how conflicts are conducted. Both manuals are imperfect, incomplete, and already struggling with new questions their drafters didn't anticipate.
Yet they represent something essential: the ongoing claim that even in warfare, especially in warfare, law matters. That nations cannot hide behind the "fog of war" to avoid legal responsibility. That adversaries can find common ground in legal principles even when they disagree violently on strategy.
The San Remo Manual made the sea a realm of law, not just conquest. The Tallinn Manual is attempting to do the same for cyberspace. Whether they succeed completely matters less than the fact that they tried—and in trying, they established that the rule of law extends to the newest and most dangerous domains humans have created.
The real question for the next generation isn't whether these manuals are perfect. It's whether we have the wisdom to update them before the next revolution in warfare arrives.
Both the San Remo Manual and Tallinn Manual remain "soft law"—influential but not binding on states. Yet their real power lies not in enforcement, but in the fact that nations cite them, debate them, and grudgingly accept their underlying premise: that even when we wage war, law still matters.
Member discussion