Earlier this year, GNI held a learning call on how companies conduct human rights due diligence of tech infrastructure services in conflict settings when their customers are governments.
The session explored how governments use tech infrastructure services in various conflict settings, how companies might understand possible impacts and harms of these uses of their services under international humanitarian law and international human rights law, and what steps companies can take to mitigate their relationships to resulting harms. This piece highlights key learnings and areas of discussion from the convening consistent with GNI’s confidentiality rules, but it does not intend to be a comprehensive review of the issues.
The convening was unfortunately very timely, as it coincided with the start of war between the United States, Israel, and Iran. At the time of the discussion, data center infrastructure damage had already been reported, and a dispute was heating up between the U.S. government and Anthropic over what was allowable use of Anthropic’s technology services by the U.S. government.
Further consideration is needed on the rights implications of government use of tech infrastructure services in conflicts
This convening built on prior conversations by GNI’s Armed Conflict Working Group, which explored tech company responsibility in conflict and led to a briefing paper. GNI organized that Working Group in partnership with the International Committee of the Red Cross (ICRC), the Stockholm International Peace Research Institute (SIPRI), and the Civil and Human Rights Clinic – George Washington University Law School (GW Law). The resulting briefing paper focused on the broad importance and implications of international humanitarian law (IHL) and international human rights law (IHRL) for tech companies. Since then, a number of GNI members have further developed critical work in this area.
Overall, when the field has considered the influence and impact of tech companies in conflict settings, there has been more focus on the content layer of tech products, rather than infrastructure capabilities. So, for this convening, we specifically wanted to highlight how tech services can conduct meaningful human rights due diligence of infrastructural capabilities, which can create distinct human rights concerns when governments use them within conflict settings.
Governments are increasingly using tech infrastructure in conflict in ways that negatively impact rights
Governments contracting with companies for military use of technology is not new. However, governments and government-owned or controlled entities are increasingly seeking to integrate a wider range of tech infrastructure services, including cloud computing and AI tools, into military activities and other uses during conflicts. This increasing prevalence of “dual-use” technology can blur the lines between what is civilian and what is military technology.
For example, there are AI and other semi-automated decision-making tools being used more directly in conflict, such as in the process of target selection and in surveillance. This can lead to real risks, including to the right to life, when user data collected via surveillance, or in some cases from user data collected through non-military functions by tech companies is linked to weapon systems.
At the same time, sometimes the same tech used in armed conflict contexts can assist with the realization of rights. For example, there are strong humanitarian use cases related to the identification of civilians in need of services. Given this, companies need to conduct rights-aware balancing in their provision of services.
Companies have responsibilities to conduct human rights due diligence, including when governments in conflict are customers
While under international humanitarian law and international human rights law, governments – and in the case of international humanitarian law, non-State armed groups – are the primary duty bearers, companies also bear responsibilities under these frameworks. For example, companies that provide tech infrastructure services, such as cloud computing and AI-enabled technologies, have responsibilities to identify and mitigate the human rights risks related to the use of these services. Companies should view these issues as part of their broader business and human rights approaches, so concerns can be addressed holistically across the business, rather than being siloed as solely a security, government affairs, or procurement issue.
Risks include use of sensitive data, enabling surveillance, facilitating discrimination, and otherwise causing, contributing to, or being directly linked to government violations of human rights or humanitarian law (see relevant resources on tech company responsibilities from the ICRC; GNI’s Policy Brief on AI Governance also has relevant recommendations for companies in conducting due diligence). There should also be scrutiny of whether and how humans will have oversight within and over these systems. Companies sometimes also offer specialized support services to governments as part of these broader contracts, and depending on the service provided, they should conduct more careful due diligence about the roles their staff might be playing and any related limits or mitigations that may be appropriate.
At the same time, companies may not have visibility into government end uses. And, of course, circumstances can often change quickly – transforming peacetime contexts, contracts, and use cases into conflict-affected high risk scenarios that may or may not have been foreseeable. This makes it particularly important for companies to conduct due diligence on the customer’s human rights record, and whether – given potential limited visibility into the end use – there will be meaningful ways to ensure that their services will not be misused.
Available safeguards to respect rights
Companies can turn to a variety of safeguards to anticipate, assess, and address the violation of rights by government use of their services in conflict. For example, they can rely on government procurement guidelines, domestic laws and regulations, company policies, contractual provisions, and technical safeguards, with each providing different and sometimes reinforcing safeguards. One key mechanism that civil society experts recommend is that companies include the ability to end contracts with governments if governments violate contractual clauses or international legal obligations.
It is worth noting that the use of these kinds of safeguard mechanisms are being challenged by governments. The U.S. government’s designation of Anthropic as a “supply chain risk,” appears to have been done in large part as a response to the fact that Anthropic tried to set some limits on the government’s use of their technology via contractual provisions. It is noteworthy that Anthropic sued to maintain the right to include limitations in their contracts, and that other practitioners and companies joined as amici (or “friends”) in their lawsuit. The resulting court decisions and contract negotiations will help determine the extent to which contractual limitations may be used to mitigate against unintended and undesired outcomes.
Developing more robust human rights due diligence practices
In conflict settings – as elsewhere – companies should engage in ongoing human rights due diligence. Within this broader context, what should human rights due diligence of tech infrastructure services look like, particularly when customers are governments in conflict settings? What can companies do to develop, implement, and improve their practices? To start, companies should operate consistently with the UN Guiding Principles for Business and Human Rights (UNGPs) and can look to the GNI Principles for guidance on how to respect privacy and free expression.
Additionally, companies can draw on established resources, such as BSR and JustPeace Lab’s toolkit, which lays out nine steps for heightened due due diligence in conflict-affected and high-risk areas. These include developing a formalized policy for conflict-sensitive HRDD, building cross-functional capacities to conduct eHRDD, scoping triggers and thresholds, conducting a conflict assessment, analyzing impacts, addressing them, communicating progress, and conducting stakeholder engagement and engagement in multistakeholder settings throughout.
During the convening, GNI company members shared some of their standard practices. Company members have teams dedicated to looking at these issues and embedding considerations in business processes and decision-making. These company processes included conducting conflict assessments informed by desk research and with understandings of international law and normative expectations for business as laid out in the UNGPs, GNI Principles, and other authoritative sources. This can include consulting resources from the UN and other credible organizations to understand the state of play in conflict-affected areas and to gain insight into rule of law considerations to inform relevant mitigations. Companies should also conduct consultation with stakeholders and seek forums like GNI to learn about best practices, under appropriate anti-trust protocols.
Where conflict breaks out in a context that had previously been conflict-free, companies typically initiate a crisis response protocol, which should include appropriate stakeholder engagement, to understand the threat actors and underlying conditions of the instability. For most companies operating directly in a conflict-affected area, their initial primary concern is guaranteeing the safety of company staff, an approach that is consistent with the GNI Principles.
As context changes in conflict periods, an important part of due diligence is awareness of the use and impact of company services. Civil society feedback, media reporting, and internal company staff concerns can be important tools in this process. If there are allegations, the level of specificity can help focus and guide internal investigations (e.g. “a company’s specific product is being used by a specific customer to do a specific harm” is easier to investigate and assess as a claim than “a company’s services are being used for harm”).
As an example, last year Microsoft investigated allegations that an Israeli military unit had used its infrastructure to store recordings of phone calls obtained through mass surveillance of civilians in Gaza, and published a report on its findings and the steps it is taking in response. In another context, during the beginning of the Russian invasion of Ukraine, Cloudflare defended the Ukrainian top-level domain and many government websites, while simultaneously pushing back on calls to cut off Internet access to Russia so the Russian people could continue to access information.
The importance of transparency
Overall, civil society experts emphasized that timeliness, continuity, and transparency are key to conducting meaningful human rights due diligence of government customers operating in conflict. If due diligence is too slow, lives can be at risk. If due diligence doesn’t happen on an ongoing basis, new risks or harms can be missed.
Finally, if due diligence is not meaningfully transparent, it is very hard for actors outside of the company to play their necessary roles in the ecosystem to protect rights. For example, civil society actors can serve as partners to companies to help surface risks, connect companies to impacted communities, and develop responsive mitigations. It could be helpful for companies to have further guidance on what kinds of transparency would be most meaningful to civil society actors.
Moving forward
In a world where conflict unfortunately seems to be increasingly common and where governments increasingly rely on infrastructure provided by multinational tech companies, these companies should be aware of and embrace their responsibilities under international humanitarian law and international human rights law, including by conducting robust human rights due diligence informed by multistakeholder engagement and providing appropriate transparency.
GNI looks forward to continuing to engage its members and partners to discuss these themes.