SynapseWargame
← Insights

Auditable AI in the command post: what legal advisors need

Accountability · 6 min read · Unclassified // Public release

Every significant Alliance decision is examined twice: once by the commander who takes it, and again - sometimes years later - by people who were not in the room. Legal advisors review it against the rules of engagement and the law of armed conflict. Inspectors-general examine it after an incident. Parliamentary committees and national inquiries examine it after an operation. Thirty-two nations retain their own standards of scrutiny, and a coalition decision must withstand all of them.

This is the environment into which AI decision-support is now being introduced, and it explains why explainability in defence procurement is not a research aspiration. It is a contractual requirement, because a capability whose outputs cannot be explained after the fact transfers unmanageable risk onto the officer who used it.

What a legal advisor actually needs

Legal advisors are not asking for model interpretability in the academic sense. They rarely need to know which parameters activated. What they need is a defensible account of the decision, and in practice that account has four components.

They need the inputs: what picture of the battlespace, adversary disposition and civilian presence was in front of the staff at the moment of decision - not the picture as later corrected. They need the assumptions, explicitly stated, because most contested decisions turn out to hinge on an assumption that was reasonable at the time and wrong in hindsight. They need the alternatives considered, since proportionality analysis asks whether a less harmful option was available and examined. And they need the chain of reasoning that connected those inputs to the recommendation the commander received.

Conventional planning tools capture almost none of this durably. The staff estimate records conclusions. Briefing slides record the preferred option. The assumptions that shaped the analysis live in working documents and in the memory of officers who have since rotated. When an inquiry asks why a course of action was chosen, the honest answer is often a reconstruction rather than a record.

Signed evidence chains

A signed evidence chain closes that gap. Each input, assumption, simulation run and recommendation is cryptographically signed at the moment it is created, and each entry references the one before it. The result is tamper-evident: any later alteration breaks the chain and is detectable by an independent verifier who does not need to trust the system operator.

Two properties make this more than a logging feature. The first is contemporaneity. Because signing happens as work proceeds rather than at export, the record reflects the decision as it actually unfolded, including the assumption that was later revised. An after-the-fact summary can be honest and still be a reconstruction; a contemporaneous signed record is evidence.

The second is replay. Reconstructing a wargame exactly as it was run - same scenario state, same model version, same adversary configuration - lets an inquiry examine the decision environment rather than only its output. It also permits the counterfactual question that inquiries always ask: if that assumption had been different, would the recommendation have changed? Sensitivity analysis answers it with the same rigour applied at the time.

Cryptographic choice matters here in a way it does not for most software. These records must remain verifiable for decades, long after a cryptographically relevant quantum computer plausibly exists. Signing with post-quantum algorithms today is what keeps a 2026 decision record defensible in the 2040s.

Why this is now a procurement requirement

Capability directorates have begun to write auditability into requirements rather than treating it as a desirable feature, and the logic is straightforward. A tool that cannot produce a decision-rationale package cannot be used for decisions that will be reviewed - which, in an Alliance headquarters, means it cannot be used for anything consequential. Auditability is what converts an interesting analytical capability into one a commander is permitted to rely on.

It also constrains the role AI may play. A system that documents, rehearses and stress-tests supports human command. A system that decides displaces accountability onto something that cannot be held accountable. SynapseWargame™ is deliberately built as the former: the commander decides, and the platform proves what the commander was shown.

Read more about the security architecture, or start with why planning cycles are too slow.

Read the SynapseWargame™ capability brief.

Capabilities, deployment models and security architecture - released to verified official addresses.

Download Capability Brief