Two Researchers Offer a Template for Washington and Beijing

Experts from the United States and China want to prevent artificial intelligence systems from making autonomous decisions about deploying nuclear weapons, and they have now put forward specific proposals they hope both governments will adopt. Melanie Sisson of the Brookings Institution and Tianjiao Jiang of Fudan University published the recommendations ahead of a planned meeting between President Trump and President Xi Jinping on September 24 — a timing that appears designed to place concrete language in front of policymakers while a high-level dialogue is still scheduled.

Rather than calling for a sweeping moratorium on military applications of AI, the two researchers concentrate on a small number of clearly defined red lines. That framing reflects an implicit judgment: the areas where American and Chinese interests most obviously overlap are also the areas where the consequences of a miscalculation would be hardest to contain.

The Red Lines the Proposals Would Draw

The recommendations spell out several prohibitions, each aimed at a specific failure mode rather than at the technology in general.

No Independent Authority to Launch

The first and most consequential rule concerns launch authority. Under the proposals, no AI system would be permitted to launch nuclear weapons on its own. The provision would close off any pathway by which an algorithm, however capable, could order a strike without a human decision standing behind it.

Nuclear Command Systems Off Limits

A second red line bars AI from being used to attack nuclear command systems. Because those systems sit at the center of a state's ability to detect, decide, and retaliate, automated operations against them carry an unusually high risk of being interpreted as preparation for a first strike. Excluding them from AI-enabled targeting is intended to remove that particular trigger.

Humans Retain Sole Control of Cyber Operations

A third provision addresses cyberspace. Humans would be required to retain sole control over AI-driven cyberattacks directed at strategic infrastructure. Cyber operations are a domain where machine-speed action is already plausible, and where the line between probing and crippling an adversary can be blurred by the pace of automated tooling.

Agreeing on What "Human Control" Actually Means

Underpinning the specific bans is a definitional problem. The proposals call on both countries to agree on a shared definition of "human control." Without that common vocabulary, each side could claim compliance while operating under standards the other does not recognize — precisely the kind of ambiguity that arms control agreements have historically struggled to close.

Standing on an Agreement Already Reached

The recommendations build on an understanding between Biden and Xi reached in November 2024. That earlier commitment established political buy-in at the top level, but it did not settle the operational questions of what is banned, who verifies compliance, or how disputes are resolved. The new proposals are an attempt to convert a statement of intent into something closer to a working rulebook.

Framing the effort as an extension of an existing understanding is a deliberate diplomatic choice. It allows both governments to present the measures as continuity rather than concession, which matters when domestic audiences on either side are inclined to read any bilateral security arrangement as a weakening of position.

A Hotline Built Around AI Incidents

Jiang also proposes creating a dedicated hotline for AI incidents. The reasoning is straightforward and worth walking through. Suppose a defensive AI system automatically responds to what it registers as suspicious activity. The other side, observing that response without context, might read it as the opening move of an attack rather than a reaction to a misread signal. A direct line between governments would let one side clarify that an incident was accidental before the situation escalates beyond the point where clarification is still useful.

In effect, the hotline is designed to break an automated loop with a human conversation — restoring the slower, deliberate decision-making that automated systems are meant to compress.

Why Some Analysts Doubt the Hotline Idea

Not everyone is convinced such a channel would function when it is needed most. Carla Freeman of Johns Hopkins University questions whether hotlines of this kind would even work. She points to the spy balloon crisis in 2023, when China did not pick up when the United States called.

That example cuts to the heart of the verification problem. A hotline is only as valuable as the willingness of both parties to answer it during a genuine crisis, and crisis moments are exactly when governments are least inclined to trust an unfamiliar channel. The objection is not that communication is unnecessary, but that institutional mechanisms need to be exercised and normalized long before an emergency makes them load-bearing.

Five Years of Warnings, No Binding Rules

This is not the first time the alarm has been raised. The National Security Commission on Artificial Intelligence called for preserving human control over nuclear weapons back in 2021. More than five years later, binding mechanisms still do not exist.

That gap — between a widely shared diagnosis and the absence of any enforceable instrument — is the central obstacle the new proposals must overcome. Expert consensus has been achieved in broad strokes: few serious voices argue that machines should decide whether to use nuclear weapons. What has proven elusive is the machinery to make that consensus binding, verifiable, and durable across changes in government.

The Narrow Window Before September 24

The proposals arrive at a moment when the two governments are preparing to meet, which gives the ideas a chance to move from the pages of a think tank paper into the preparatory conversations that shape a summit agenda. Whether they do, and whether any of the red lines survive contact with the negotiating process, will depend on factors that lie well outside the researchers' control.

What the proposals do accomplish is to make the case concrete. Instead of general warnings about the risks of military AI, they identify specific prohibitions, a definitional task, and a crisis communication channel — a set of items that could plausibly be discussed, adopted in part, or rejected outright. In a policy area where the stakes are measured in minutes and miles, that specificity is itself a contribution: it turns an abstract worry into a list of decisions decision-makers can actually make.

This article is based on reporting by The Decoder. Read the original article.

Originally published on the-decoder.com