Armed Conflict Foreign Relations & International Law

In the Line of Fire: Legal Risks for Tech in Conflict Zones

Adam Hickey, Veronica Glick, Rohith George, Rachael O'Grady
Tuesday, August 18, 2026, 10:00 AM

From targetability to liability, tech companies face expanding risks in conflict zones.

U.S. reverse-engineered version of the Iranian Shahed drone (Cpl. Kayla McGuire, https://tinyurl.com/59ynfv8r; Public Domain)

On March 2, Iranian drones struck data centers belonging to a U.S. company in the United Arab Emirates and Bahrain. Iran’s Islamic Revolutionary Guard Corps claimed responsibility, asserting that the facilities supported “the enemy’s military and intelligence activities.” The attacks caused structural damage, power disruptions, and service outages affecting banks, payment platforms, and consumer applications across the Persian Gulf region. These strikes highlight the unique challenges technology companies face when their civilian infrastructure becomes entangled—whether accurately or not—with government and military operations in a period of escalating geopolitical conflict

Dual-use technology refers to products or services developed for commercial purposes that can also be applied to military or intelligence operations. That overlap can put a company’s infrastructure or personnel in the crosshairs when they are associated with military operations, whether accurately or not. This association, or perceived association, depends on a range of factors including where the infrastructure is physically located and how the products are used in conflict zones.

This article sets out that the risks are immediate and legally complex, spanning international humanitarian law, contract law, and investment treaty arbitration, among others. It concludes with steps that companies can consider taking now, including communicating the civilian nature of their operations, separating military and civilian infrastructure where feasible, anticipating service disruptions when negotiating contracts, and mapping available investment treaty protections.

Targetability Under International Humanitarian Law

Under international humanitarian law (IHL), civilians and civilian objects are protected from attack. However, that protection is not absolute. Article 52(2) of Additional Protocol I to the Geneva Conventions defines “military objectives” as objects that by their “nature, location, purpose, or use make an effective contribution to military action and whose partial or total destruction, capture or neutralization, in the circumstances ruling at the time, offers a definite military advantage” (emphasis added). The Department of Defense’s Law of War Manual, Section 5.6.3, also incorporates this language. There is debate over what civilian objects meet this definition, but technology infrastructure that does so may be targeted lawfully under international law during an armed conflict. As partnerships between technology companies and governments develop, an increasing number of private-sector assets risk being deemed legitimate military targets during wartime.

One challenge for technology companies lies in the nature of modern cloud infrastructure, where military-related data may be separated from civilian data through logical controls (such as access controls and virtual separation), but still rely on the same physical infrastructure. This raises the risk that actors in conflict zones will argue that the physical infrastructure meets the definition of providing an “effective contribution” to military action.

The attacks on data centers underscore that this is not a theoretical risk. In the months preceding and following the March 2026 strikes, U.S. government agencies, including the Cybersecurity and Infrastructure Security Agency and the National Security Agency, issued repeated warnings that Iranian state-sponsored actors were actively targeting critical infrastructure through cyber operations. Iran justified the strikes by arguing that the U.S. military had used the data centers targeted to host systems for intelligence analysis and war simulations. On March 5, U.S. and Israeli forces reportedly bombed at least two data centers in Tehran in response. Subsequently, news agencies in Iran published a list of dozens of regional facilities, including data centers owned by major U.S. technology companies and others, designating them as “enemy technology infrastructure” suitable for targeting.

As governments, international organizations, and the private sector work to address protections for civilian digital infrastructure, several initiatives and proposals have surfaced. At the multilateral level, for example, the UN Group of Governmental Experts and its successor Open-Ended Working Group have produced nonbinding norms since 2015, which provide that states should not conduct or knowingly allow cyber operations that damage critical infrastructure servicing the public.

One operationally concrete proposal that has emerged is the International Committee of the Red Cross’s (ICRC) “digital emblem” initiative, which seeks to develop a cryptographically secured, machine-readable marker that would signal in cyberspace the same legal protections for digital assets that the physical red cross signals in the physical world. The project seeks to make existing IHL protections more visible and operationally recognizable in the digital environment by marking the digital infrastructure of hospitals, certain humanitarian organizations, and other protected entities to indicate their protected status.

This initiative has gained some traction, including an Internet Engineering Task Force working group charter in July 2025, a path to becoming an actual internet protocol, and a prototype technology deployment announced in July 2026. Although the digital emblem may not address the dual-use infrastructure challenges that technology companies face, it may help government users distinguish between combatants and noncombatants in ways that tech companies may want to enable for governments that are using their products for military purposes.

Risks to Personnel: Direct Participation in Hostilities

In addition to infrastructure considerations, companies should ensure that protections are in place to limit the risk that employees may be considered lawful targets in conflict. Under IHL, private-sector employees are generally classified as civilians and protected from direct attack. However, that protection ends “for such time as” an employee “directly participates in hostilities” (DPH).

There is considerable debate over what actions meet the DPH threshold. Interpretive commentary from the ICRC requires all three of the following elements:

  • Threshold of harm: likely to harm a party’s military operations or capacity, or to kill, injure, or damage protected persons or objects.
  • Direct causation: a direct causal link between the act and the resulting harm (or a coordinated operation of which it forms part).
  • Belligerent nexus: specifically designed to cause harm in support of one party and to the detriment of another.

The DPH analysis becomes even more complicated in the context of cyberspace. An aggressive adversary may argue that employees engaged in offensive cyber operations, designing software for use in military cyber operations, or refining artificial intelligence models used to identify military targets could be characterized as directly participating in hostilities on the theory that such activities may cause harm that is specifically designated to the detriment of the adversary’s military capacity.

Although the DPH threshold remains a contested area, companies can take steps to ensure that policies, public statements, and employee conduct do not inadvertently create confusion. Proactive measures—such as educating employees on the significance of certain workflows and their public statements, and signaling to potential adversaries that employees are not participating in hostilities—can help minimize this exposure. Beyond avoiding confusion, companies could proactively issue internal or external policy statements clarifying the “red lines” they will not cross regarding what is enabled for government customers.

Contractual Liability and the Force Majeure Problem

Force majeure clauses are contractual provisions that excuse a party from performing its obligations when extraordinary events beyond its control occur: typically natural disasters, wars, or government actions that make performance impracticable or impossible. These clauses have taken on renewed significance for businesses operating in or near conflict zones. Parties have increasingly invoked the clauses in connection with armed conflicts, government-imposed sanctions, trade embargoes, and supply chain disruptions. The recent declarations across the Persian Gulf energy sector following strikes and disruption to the Strait of Hormuz illustrate how quickly conflict can move a company from routine performance to a breakdown in operating conditions.

Whether a party can successfully rely on a force majeure provision depends heavily on the precise drafting of the clause—including whether it expressly enumerates war, hostilities, terrorism, or government action as qualifying events, or whether it relies on more general catch-all language requiring the event to be unforeseeable and beyond reasonable control. Some U.S. government contracts, for example, may preclude such arguments by requiring performance of “essential contractor service” or “mission-essential functions” even during crises.

When relying on catch-all language, businesses with operations in geopolitically volatile regions face the challenge of demonstrating that the disruption was truly unforeseeable at the time of contracting, as counterparties may argue that the risk of conflict was known or reasonably anticipated when the agreement was executed. Courts and tribunals have historically scrutinized whether a party took reasonable steps to mitigate the impact of the force majeure event; a business that continued to operate in a deteriorating security environment without contingency planning may find its invocation of the clause weakened.

Moreover, the intersection of force majeure clauses with sanctions regimes presents an additional layer of analysis: A party may be unable to perform not because of the conflict itself, but because of governmental restrictions imposed in response to it, raising questions about whether regulatory action constitutes a separate qualifying event or merely a foreseeable consequence of the underlying geopolitical situation. In light of these dynamics, businesses with exposure to conflict zones should review their contractual frameworks to ensure that force majeure provisions are drafted with sufficient specificity to capture the range of disruptions that modern geopolitical instability may produce—including not only direct hostilities but also secondary effects such as sanctions, export controls, banking restrictions, and the collapse of logistics infrastructure.

Recourse Against State Actors

In a conflict scenario, a U.S. technology company operating data centers in a foreign state may find that its host government suspends contractual payments, requisitions facilities for emergency use, restricts site access during ongoing hostilities, or fails to provide adequate protection against attacks by third-party belligerents. In these circumstances, the company may consider the following avenues of recourse against the host state.

Where a technology company has a direct contractual relationship with a state entity—whether a government ministry, state-owned enterprise, or sovereign instrumentality—the company’s primary recourse in the event of a dispute will typically lie in the contract itself. State entities that enter into a commercial contract are, as a matter of principle, bound by the contract’s provisions in the same manner as any private party. This includes limitations on liability, indemnification obligations, and enforceability.

Subject to any force majeure clause or other contractual mechanism that may excuse performance, the state entity remains liable for breach in accordance with the terms of the agreement. The practical enforcement of those contractual rights, however, may be affected by doctrines of sovereign immunity. Although many jurisdictions recognize exceptions to immunity for commercial transactions, the scope of those exceptions—and the extent to which they permit proceedings against a state or enforcement against state assets—varies considerably. In the United States, for example, disputes with federal agencies are governed by statutory regimes such as the Contract Disputes Act. Other jurisdictions apply their own sovereign immunity frameworks, which may affect the forum, procedure, or available remedies.

Critically, where the contract includes an arbitration clause, the state entity will also be bound by that dispute resolution mechanism. International commercial arbitration is typically the preferred mechanism for resolving disputes with foreign state counterparties, offering neutrality, confidentiality, and—crucially—enforceability. Most major institutional rules, including those of the International Chamber of Commerce, London Court of International Arbitration, Stockholm Chamber of Commerce, and Singapore International Arbitration Centre, provide for emergency arbitration procedures, enabling a claimant to seek urgent interim relief (such as asset-freezing orders or injunctions to prevent the dissipation of funds) before a tribunal is fully constituted. This can be particularly valuable in a conflict scenario where there is a risk that a state party may seek to place assets beyond reach.

In the event of a successful award, enforcement can be pursued under the Convention on the Recognition and Enforcement of Foreign Arbitral Awards against the state’s commercial assets in any of the convention’s 170-plus contracting states, giving the successful party a genuinely global enforcement landscape (although, in certain jurisdictions, sovereign immunity defenses may in practice limit the pool of assets available for execution).

Beyond direct contractual claims, technology companies with foreign investments may also benefit from protections afforded under bilateral or multilateral investment treaties. Where a company’s home country has concluded an investment treaty with the host country where the company’s investments are located, the company may be able to bring a claim directly against the host country before an international tribunal—typically under the International Centre for Settlement of Investment Disputes Convention or the United Nations Commission on International Trade Law Arbitration Rules—for conduct that damages its investment. The precise scope of protection available will depend on the wording of the applicable treaty, as investment treaties vary considerably in their drafting and coverage.

Investment treaties typically include protections such as most favored nation treatment (requiring treatment no less favorable than that accorded to third-state investors), national treatment (requiring treatment no less favorable than that accorded to domestic investors), and full protection and security (requiring due diligence in protecting investments from harm). However, national security carve-outs, which permit measures taken in pursuit of essential security interests, may limit available remedies during active hostilities.

Practical Recommendations

This article is not intended to cover all challenges companies operating in conflict-affected regions or providing services to government and military clients may face. We do not address, for example, regulatory liability, tort or negligence claims, or insurance policy coverage exclusions. However, the recommendations below may be helpful in assessing a company’s level of risk.

Assess IHL Exposure

Consider regularly assessing the factors that impact whether business operations may be deemed “military objectives” or whether employee activities could be considered “directly participating in hostilities.” Assess whether enhanced policies that educate employees about their public statements could reduce the risk of confusion and whether it could impact the company’s internal or external exposure.

Publicize the Civilian Nature of Facilities and Operations

Consider engaging with host governments and, where possible, communicating broadly to potential adversaries the civilian nature of facilities and operations. This could include information about potential civilian harm from an attack on company facilities—information that state aggressors are legally obligated to consider under IHL proportionality requirements.

Work Closely with IT / Security to Manage Military and Civilian Infrastructure

To reduce the risk that civilian infrastructure qualifies as a military objective, companies should consider options for tagging or separating workflows. Tagging could involve, for example, applying metadata labels to distinguish military-related workloads from civilian ones. Separating means routing them through distinct infrastructure paths. For many technology companies, however, physically and logically separating military work from civilian services may not be feasible at this time; for example, when a government customer purchases commercial products or services, it may not be possible to separate the two except at the end-user level.

Implement Cybersecurity Fundamentals for Conflict-Zone Operations

Companies operating in or near conflict zones, or that supply dual-use technologies, should treat baseline cybersecurity measures as mission-critical. Reducing attack surfaces and containing the blast radius of any intrusions are crucial for operational resilience. Key measures include:

  • Network segmentation: isolating critical systems so that a compromise of one segment does not cascade across the enterprise.
  • Multi-factor authentication: requiring multi-factor authentication for all privileged and administrative access.
  • Patch management: maintaining accelerated and risk-based patching cycles for internet-facing systems.
  • Conflict-adapted incident response: testing and training on incident response plans to account for wartime scenarios, including degraded communications, personnel evacuation, and coordination with government cyber agencies.

Address Contractual Gaps

These risks are best managed through deliberate drafting rather than after-the-fact remedies. Companies with conflict-zone exposure should confirm that their force majeure, change-in-law, suspension, and termination provisions expressly capture war, sanctions, export controls, and government action, with clear notice mechanics and a termination trigger for prolonged disruption.

Additionally, companies should evaluate whether their public-sector customers are prepared to extend indemnification for harms arising from the customer’s own use of the contracted goods or services. This protection is particularly relevant in national security scenarios. This indemnification, however, is typically available only under narrow circumstances, such as where the agency has specifically designated the risk as “unusually hazardous.

Review Investment Treaty Coverage

Companies with significant infrastructure in host states should assess whether a bilateral or multilateral investment treaty is in force and understand the specific protections available.

Anticipate National Security Carve-Outs

When evaluating recourse against a host state, companies should consider the potential for national security exceptions to limit available remedies, particularly during active hostilities. This can help inform realistic assessments of litigation risk.

*          *          *

While the question of what protections apply to privately held infrastructure that inadvertently or intentionally becomes entangled with government operations and infrastructure during hostilities is not new, the March 2026 data center strikes have highlighted how this manifests in a modern context. Technology companies can no longer assume that all states will view their business as purely commercial enterprises. In an era of rising geopolitical tensions, proactively understanding applicable international and domestic laws will be increasingly important for protecting companies, their employees, and their infrastructure.

The authors thank Dassi Diament for her research.


Adam Hickey works at the law firm Mayer Brown and specializes in cybersecurity, sanctions, export controls, the Foreign Agents Registration Act (FARA), CFIUS, and other national security authorities.
Veronica Glick works at the law firm Mayer Brown and focuses on cybersecurity, emerging technology, crisis response, investigations, and national security. Veronica was a Council on Foreign Relations International Affairs Fellow.
Rohith George works at the law firm Mayer Brown as co-leader of the firm’s Technology and IP Transactions Group.
Rachael O’Grady is a solicitor advocate at Mayer Brown LLP. She concentrates on international commercial and bilateral investment treaty arbitration and public international law.
}

Subscribe to Lawfare