I. Introduction
When a State orders its telecommunications providers to suspend internet access across a conflict-affected region, the consequences for civilian life are immediate. Hospitals lose access to electronic health records, aid convoys lose GPS coordination, and families are unable to locate displaced members and confirm their safety and whereabouts. Yet International Humanitarian Law (IHL) has developed no coherent framework for evaluating this act. A prominent strand of scholarship applies the conduct of hostilities framework, asking whether connectivity infrastructure constitutes a military objective under Article 52(2) of Additional Protocol I (AP I), and whether a shutdown qualifies as an ‘attack’ triggering proportionality and precaution obligations. Schmitt’s foundational work on cyber operations and Droege’s influential 2012 ICRC analysis both proceed within this frame. While these contributions have improved how IHL applies to offensive cyber operations, the article argues that the framework does not accurately represent the shutdowns it claims to address.
This article advances three major arguments. First, in conflicts involving prolonged effective territorial control, Gaza, Tigray and Nagorno-Karabakh being the most documented examples, the governing framework is occupation law under the Geneva Convention IV (GC IV). This approach is applied where the stipulated degree of effective territorial control is established, notwithstanding the differing legal characterisations. While the conduct of hostilities framework governs the legality of attacks, occupation law governs the affirmative obligations arising from the administration of civilian life and infrastructure without requiring the prior establishment of an ‘attack’. Second, internet shutdowns constitute a structurally novel category of harm, i.e., infrastructural exclusion. IHL’s object-destruction paradigm lacks adequate vocabulary, and the access-based logic of AP I Article 54 provides the most textually grounded, if underdeveloped, doctrinal foundation. Third, the private Internet Service Providers (ISPs) that execute shutdown orders occupy a lacuna of complicity that existing scholarship has not addressed. Taken together, the three arguments reveal a common lacuna. The vocabulary of IHL primarily focuses onobjects and cannot adequately address an occupier’s administrative silence. As a result, the law resorts to asking whether any breaches have occurred rather than whether anything has been withheld, and it is this same blind spot that causes the intermediaries who are responsible for the withholding to vanish completely from sight.
II. Why the Conduct of Hostilities Analysis Mischaracterises the Problem
In scholarly works, connectivity disruptions are often analysed through a targeting lens. Definitions of “cyber-attack” under Schmitt, Droege and the Tallinn Manual 2.0 are all output-oriented. Each requires the operation to cause injury, death, damage, destruction or a change in the functioning of the targeted system, following the ‘acts of violence’ standard in AP I Article 49.
This output-oriented framework is structurally ill-suited to State-ordered internet shutdowns, which deny access to functioning infrastructure without altering its underlying operation. Shutdowns in Gaza, Tigray, Myanmar’s Rakhine State, and Nagorno-Karabakh were not executed through cyber intrusions that caused loss of functionality in targeted infrastructure. They were executed by government directives to domestic ISPs, i.e., civilian companies operating under domestic licensing law, to cease providing service. The infrastructure remained intact while the legal authorisation to operate it was withdrawn. No object was attacked, damaged or destroyed; hence, no ‘attack’ occurred under the definition of Article 49.
The ICRC argues that interpreting the term ‘attack’ too restrictively is incompatible with the purpose of IHL. The article agrees with that principle but questions the practice of applying rules defined in the context of violence to situations they do not explicitly cover. This approach is less effective than establishing the legal framework that governs each situation.
III. Occupation Law as the Governing Framework: Affirmative Duties and the Maintenance Obligation
There is a recurring characteristic among the conflicts where internet shutdowns have been thoroughly documented. The party responsible for the shutdown effectively controls the territory and civilian population involved, which meets the criteria for occupation law under GC IV. Critically, as Henckaerts and Doswald-Beck confirm, several of the civilian-protection obligations reflected in GC IV also correspond to customary IHL rules applicable in both international and non-international armed conflicts.
The law of occupation limits the controlling power not only as a belligerent limited in its capacity to harm, but also as a de facto administrator with positive obligations. The occupying power shall ensure food and medical supplies (Art. 55), maintain hospital services (Art. 56), and refrain from measures denying guaranteed rights under GC IV to the population (Art. 64).
The violation of these obligations does not require proof of an attack, but only proof of an administrative act that undermines the infrastructure of civilian survival. Hospitals depend on Internet-based records, ambulance dispatch and coordination with humanitarian agencies to function. Article 56 does not simply prohibit interference with hospitals but obligates the occupying power to keep them functioning. That distinction matters because a disruption-based interpretation requires showing that the shutdown was directed at the hospital, which is difficult to sustain where the order targets network infrastructure instead of the medical facility itself. A maintenance-based interpretation instead asks whether hospital services remain capable of functioning under the occupier’s control, making the precise mechanism of disruption immaterial. An order to shut down connectivity therefore violates Article 56 without requiring the shutdown to constitute an attack.
Under Article 64, the necessity test permits measures only when they are required for the occupier’s security or the orderly administration of the territory. A shutdown should only be implemented where continued connectivity poses a substantial security or administrative threat that cannot be addressed through a more targeted restriction. If the issue stems from a particular network, location or service, addressing just that element would sufficiently manage the risk without disconnecting the wider civilian population. Thus, a blanket shutdown must be justified by demonstrating why narrower measures are insufficient. When such a shutdown disrupts hospitals and hampers humanitarian coordination without valid justification, it exceeds the requirements of necessity and does not comply with the standards set by Article 64.
IV. Infrastructural Exclusion: A Category of Harm IHL Has Never Encountered
The failure of the conduct-of-hostilities framework to reach administrative shutdowns exposes a limitation in the rules governing attacks on civilian objects. The assumption is that harming civilians requires harming physical objects. From the ban on attacking civilian objects in Additional Protocol I Article 52 to the protected status of medical units under Article 19 of Geneva Convention IV, IHL’s focus on protecting objects assumes that civilian harm arises from damaging protective resources. Droege noted that IHL was not originally designed to deal with cyber operations. However, a critical issue the literature has not fully examined is that internet shutdowns mark an even greater departure from traditional norms. More than just cyber operations, these are legal actions that can harm civilians without directly impacting any physical object.
Here, harm came from the withdrawal of legal permission to use the infrastructure rather than any attack. This article refers to this situation as infrastructural exclusion, which means the intentional administrative removal of a civilian population from functional infrastructure that still exists and operates.
Infrastructural exclusion differs from physical destruction because it can be reversed almost immediately. This reversibility makes it appealing as a tool for managing conflict and has allowed it to avoid legal scrutiny. The argument that the suffering caused by shutdowns is acceptable because the shutdowns can be lifted turns civilian protection logic on its head.
The closest legal basis is found in Additional Protocol I Article 54, which prohibits starvation as a method of warfare. This rule applies not just to destruction but also to denying civilians access to objects vital for survival. However, the drafters framed this provision around physical acts, not administrative denial of digital access while the resource remains physically intact. Extending Article 54 to digital connectivity therefore involves a legal interpretation rather than a simple application of established law.
Identifying infrastructural exclusion as a specific category within IHL addresses a significant evidentiary challenge. The current targeting framework demands proof of disproportionate violence, which can be hard to establish when harm results from administrative decisions without tangible evidence.
In contrast, an access-based framework examines whether essential civilian survival infrastructure has been disrupted, thereby making civilian functions impossible.
V. The Complicity Lacuna: ISPs, Domestic Orders and IHL Responsibility
A key aspect of shutdown accountability is the legal standing of the private companies that implement them. Shutdowns are implemented by privately owned ISPs and mobile network operators that receive directives from the State and follow them. The State initiates the harm while the company enables it.
Under the ILC Articles on State Responsibility, private conduct carried out on a State’s instructions or under its direction is attributable to the State under Article 8. Where a licensing regime makes compliance legally compulsory, Article 5 may provide an alternative basis for attribution because the ISP is then exercising delegated governmental authority. In either case, an ISP executing a shutdown order is not acting independently for the purposes of State attribution.
The more difficult question is whether IHL imposes any obligation on the ISP itself, given that IHL binds States and organised armed groups rather than telecommunications companies. This does not mean that ISPs operate without any relevant framework. The UN Guiding Principles on Business and Human Rights recognise a non-binding corporate responsibility to avoid contributing to human rights harm, while the UN Human Rights Council’s 2022 report went further by calling on ISPs to conduct due diligence to mitigate the risk of shutdowns. The gap is, however, the absence of an IHL-specific obligation which could be enforced on ISPs in armed conflict. This is the narrower gap that needs to be addressed. The Access Now data records over 296 incidents in 2024, each involving private carrier compliance, underscoring the practical significance of that gap.
VI. Conclusion
IHL was designed for a world in which the greatest threat to civilian life was physical destruction, and its civilian protection architecture was organised around protecting people by protecting the objects they depend on. Internet shutdowns expose the failings of this architecture. Until IHL recognises access as an independent legal interest, distinct from yet equally fundamental to the physical integrity of protected objects, the law will remain silent on the issue, and States will continue to destroy civilian life through administrative orders.
Three consequences follow from this framework. First, a claimant challenging a shutdown would no longer need to demonstrate that the shutdown constituted an attack on connectivity infrastructure. Instead, the focus would shift to whether connectivity was intentionally withdrawn, whether the withdrawal occurred under the effective control of the responsible party and whether this loss of access negatively affected protected civilian functions. This follows from treating the shutdown as infrastructural exclusion rather than physical destruction. Second, occupation law would move from a background obligation to the primary framework for evaluating such conduct, with Articles 55, 56 and 64 applied directly to the shutdown rather than treated as incidental. Third, the attribution framework would close the gap created by the ISP’s intermediary role. If a shutdown executed by an ISP can be attributed to the State under Articles 5 or 8 of the ILC Articles on State Responsibility, the State cannot evade responsibility merely because the immediate act of disconnection was performed by a private operator acting under its instructions or authority.
The proposed framework does not seek to create new categories of treaty obligations. Instead, it focuses on applying existing IHL to forms of civilian harm that its traditional categories do not effectively capture. Acknowledging this gap is the first step towards ensuring that technological changes do not undermine the practical effectiveness of existing civilian-protection rules.
Ruchi Kharb is a third-year B.A. LL.B. (Hons.) Student at Dharmashastra National Law University, Jabalpur, India. She is an avid researcher in the fields of International Law, Arbitration and Data Protection.
PC: Pinterest / hoang duong
