Michael Schmitt and the 1999 Blueprint for Digital War

By Harlan Pryce ·

A military academy legal framework sought to redefine the 'use of force' to allow Washington to strike foreign networks without triggering a formal state of war.

A digital strike can disable a city's power grid or blind a nation's radar without a single soldier crossing a border, yet the victim may never have the legal standing to call it an act of war. This invisibility is not a technical glitch; it is a legal design. By the time the world woke up to the reality of cyber-conflict, the American military establishment had already spent years building the intellectual scaffolding to ensure their operations stayed just below the threshold of 'force.'

I am working here from the archive's curated description of the paper, as the full pages are not in the public hand. The record is a June 1999 article titled "Computer Network Attack and the Use of Force in International Law: Thoughts on a Normative Framework," authored by Michael N. Schmitt. Schmitt, an international law scholar who would later hold distinguished chairs at the University of Reading and West Point, wrote the piece while affiliated with the United States Air Force Academy, the service academy that trains the officer corps for the Air Force and Space Force.

"Wrongful Use of Force"

The document focuses on a singular, cold calculation: "when does a computer network attack conducted by, or on behalf of, a state constitute a wrongful use of force under international law?" According to the public record, Schmitt specializes in international humanitarian law and the use of force, the very rules that dictate when a state can legally kill or destroy. In the context of 1999, this was not a philosophical inquiry. It was a search for the line.

By framing the issue as a search for a "normative framework," the record shows an effort to standardize the definition of a cyber-attack. If the U.S. could define "force" narrowly—perhaps limiting it to physical destruction or death—it could effectively authorize a vast array of disruptive attacks, from data erasure to systemic crashes, while claiming that no "force" had been used. This is the alchemy of modern covert operations: transforming an act of aggression into a legal non-event.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

The Hayden Synchronicity

The timing of Schmitt’s framework is the key to the story. In June 1999, as Schmitt was defining the legal boundaries of attack, other arms of the security state were tightening the grip on the tools of execution. In July 1999, Michael Hayden, the director of the National Security Agency who spent the late nineties refining the state's ability to monitor internal and external threats, issued a report on "The Insider Threat to U.S. Government Information Systems."

While Schmitt was building the door through which the U.S. could exit international law, Hayden was locking the house. At the same moment, the Army Science Board was filing a "Summer Study Final Report" to prioritize "Army Space Needs." The connection is a synchronized pivot. Washington was not merely exploring the internet; it was integrating cyber, space, and intelligence into a single, seamless apparatus of power. The legalist, the spymaster, and the strategist were all working the same problem in the same summer: how to dominate a domain where the old rules of war did not apply.

There is a brutal irony in the calendar. On June 24, 1999, the U.S. Embassy in Jakarta was sending telegrams to the State Department describing a "scorched earth policy" in East Timor. While the American diplomatic machine watched a physical genocide unfold in the Pacific, its military academics were in Colorado, calmly debating the "normative framework" for digital aggression. The record shows a state capable of profound empathy for the victims of scorched earth while simultaneously drafting the manual for the digital equivalent.

The Private Network Blind Spot

One of the most telling aspects of the record is what it ignores. The description of Schmitt’s work focuses on attacks conducted "by, or on behalf of, a state." It treats the digital battlefield as a clash of sovereign powers. However, the public record from the same month shows that the Department of Homeland Security and the NSTAC Network Group were reporting on the "implications of electronic commerce.

Cyber-warfare does not happen on a government-owned highway; it happens on private cables, through private routers, and across civilian servers. By treating the "use of force" as a state-to-state legal matter, the framework effectively erases the private citizen and the private company from the equation. The civilian infrastructure becomes a mere conduit—a ghost in the machine—that the state can compromise or destroy without acknowledging the violation of private property or civilian safety. The legal framework is designed to protect the attacker's sovereignty, not the victim's infrastructure.

A Pre-Clearance Exercise

If the shape of this file is what it appears to be, this was never a theoretical exploration. The desk's reading is that this document was a legal pre-clearance exercise for an existing offensive capability. In military academia, when the conversation shifts from the technical "how" to the legal "when," it is because the "how" has already been solved. The Air Force Academy was not asking if they could attack; they were asking how to do it without being called a criminal in the eyes of the world.

The pattern suggests that the "normative framework" was a sanitized version of a classified operational doctrine. By publishing these "thoughts" in an unclassified format, the U.S. was signaling to the international community that it intended to set the rules of the game. It was an act of intellectual colonization: defining the terms of cyber-warfare before any other nation could establish a competing standard.

This framework was designed to provide plausible deniability by pushing the threshold of "force" as high as possible. If the threshold is high, the gap between "espionage" (which is tolerated) and "attack" (which is a crime) becomes a wide, grey canyon. That canyon is where the most effective covert operations live. The desk's reading is that the still-withheld operational pages from this era would show a strategic decoupling: the legalists like Schmitt were tasked with defining the rules of engagement in a way that ensured the intelligence community would never actually break them.

Ultimately, the cost of this legal gymnastics was paid by the global south and the civilian networks that now underpin every facet of human life. By decoupling the legal definition of "force" from the actual impact of a digital strike, Washington ensured it could break things in the dark and call it "normative." The pattern established in 1999 remains the operational standard today: the attack is real, the damage is permanent, but the legal record remains clean.

Sources

  1. Michael N. Schmitt, United States Air Force Academy,Computer Network Attack and the Use of Force in International Law: Thoughts on a Normative Framework, June 1999. Unclassified. — National Security Archive (GWU)
  2. Document PDF (Michael N. Schmitt, United States Air Force Academy,Computer Network Attack and the Use of Force in International Law: Thoughts on a Normative Framework, June 1999. Unclassified.)
  3. Background: Michael N. Schmitt — Wikipedia