Aggregating Illegality: The Accumulation of Events Doctrine in Contemporary Challenges
A legal analysis argues that international law needs to evolve to address AI-assisted ransomware campaigns, specifically by applying the accumulation of events doctrine to treat repeated cyberattacks as a collectively unlawful act triggering state accountability.
Why this matters: Ransomware attacks rarely happen once. Hostile actors run long campaigns — many smaller hits that each fall below the threshold that would force a legal response under international law. That gap is a feature, not a bug, for the people running these campaigns. The accumulation doctrine is a way to close it: stack the harm together, and suddenly accountability becomes possible. For anyone whose hospital, school, or infrastructure has been hit, the question of who answers for it matters more than the legal theory used to get there.
Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.