With the increasing application of artificial intelligence and autonomy in cyberspace, there is little doubt that “autonomous cyber capabilities” (ACC) – software agents that are programmed to carry out specific tasks through cyberspace without real-time human control or oversight – will be deployed in future armed conflicts. Yet, ACC’s lack of real-time human control and the risk of unpredictable, unreliable and unexplainable behaviour raise important concerns as to their use in compliance with international humanitarian law (IHL). This article explores whether due diligence may be a valuable framework to mitigate the risks associated with ACC and avoid unintended violations of IHL. Notably, it contends that due diligence is a chapeau obligation for several IHL norms that require States to undertake all appropriate measures to ensure the development and use of ACC in compliance with IHL, and it provides examples of diligent measures that States shall adopt.