Pillar analysis

Human-in-command and DoDD 3000.09: autonomy without autonomous engagement

DoD Directive 3000.09 governs autonomy in weapon systems. It requires that such systems allow commanders and operators to exercise appropriate human judgment over the use of force. Human-in-command means a person authorizes every effect — a decision-support system may reason and recommend, but it never arms, fires, or engages on its own.

Published

  • doctrine
  • responsible-ai
  • human-in-command

DoD Directive 3000.09 is the Department of Defense policy on autonomy in weapon systems. Its core requirement is straightforward: such systems must be designed so that commanders and operators can exercise appropriate levels of human judgment over the use of force. Human-in-command is how that requirement is met in practice — a person authorizes every effect. A decision-support system may reason and recommend all day, but it never arms, fires, or engages on its own.

What the directive requires

The directive does not ban autonomy. It requires that autonomy be governed — that systems be designed, tested, and used so a human retains appropriate judgment over the use of force, with safeguards against unintended engagements. The practical consequences for any system that touches the kill chain are design consequences: there must be a point where a human decides, that point must be real rather than a rubber stamp, and the system must behave predictably around it.

Human-in-command, precisely

It helps to be precise about degrees of human involvement:

  • Human-in-the-loop — a human must act for an effect to occur.
  • Human-on-the-loop — a human supervises and can intervene while the system runs.
  • Human-in-command — the authorizing decision for every effect rests with a person who can see the situation and be held accountable.

The distinction that matters is between sensing and recommending, which a machine can do continuously, and authorizing an effect, which a person commits to deliberately.

Where an AI co-pilot fits

An on-box co-pilot is compatible with this doctrine as long as its role stops at recommendation. It can rank tracks, draft a recommended course of action, and surface the evidence behind it — and then wait. That is exactly the boundary BlackEcho is built to. It reasons over the fused picture and recommends; it never selects or engages a target on its own. The line is not a setting to be toggled; it is the design.

Making the gate real

A human authorization is only meaningful if it is deliberate and recorded. In DaggerOS, every effect passes one Human Gate: a control a person must actively sustain to authorize, not a dialog to click past. The moment of authorization — who, what, when, and the picture it was based on — is written to a tamper-evident, SHA-256-chained record. That record is what lets an after-action review reconstruct not just what happened, but what was known and decided at the time. You can verify how such a record resists tampering in Seal-It.

Why this is a buying criterion, not a slogan

For program offices, responsible-autonomy posture is a real evaluation criterion, not marketing. A system that keeps a human in command and proves it with an auditable record is easier to field, easier to defend in review, and aligned with policy. See responsible AI and the multi-domain sensing doctrine for how the gate fits the larger picture.

Frequently asked

What is DoDD 3000.09?

DoD Directive 3000.09 is the Department of Defense policy on autonomy in weapon systems. It requires that these systems be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force.

What does human-in-command mean?

Human-in-command means a person holds authority over the decision to apply an effect and actively authorizes it. It is stronger than a human merely watching; the effect does not happen unless a human commits to it.

Is an AI co-pilot allowed under DoDD 3000.09?

Yes, when it reasons and recommends but does not select or engage targets on its own. A co-pilot that ranks tracks and drafts a recommendation, leaving authorization to a human, keeps appropriate human judgment in the loop.

What is the difference between human-in-the-loop and human-on-the-loop?

Human-in-the-loop means a human must act for an effect to occur. Human-on-the-loop means a human supervises and can intervene while the system operates. Human-in-command, as used here, keeps the authorizing decision with a person for every effect.

Related mission domains