i
DATAIST
News · 2026-09-18

US and Chinese experts propose four red lines for nuclear AI

@neuronium_ai @neuronium_ai

American and Chinese experts have put their names to a joint set of red lines that would keep artificial intelligence out of nuclear decision-making. The recommendations extend the understanding Joe Biden and Xi Jinping reached in November 2024, and they are recommendations only: nothing in them binds either government to anything.

Cover: US and Chinese experts propose four red lines for nuclear AI

American and Chinese experts have put their names to a joint set of red lines that would keep artificial intelligence out of nuclear decision-making. The recommendations extend the understanding Joe Biden and Xi Jinping reached in November 2024, and they are recommendations only: nothing in them binds either government to anything.

The authors set out four limits:

no AI system should launch nuclear weapons on its own;

AI must not be allowed to attack nuclear command systems;

decisions on cyberattacks against strategic infrastructure must stay exclusively with humans;

the United States and China should agree on a single definition of "human control".

The first three are prohibitions on machines. The fourth is the only one that asks the two governments to do work, and it is the one everything else rests on. Without a shared definition of human control, each side can claim compliance with the first three while meaning something different by them — a human in the decision loop, a human who can veto a recommendation in seconds, or a human who signed off on the targeting policy months earlier. That gap is where a bilateral understanding either becomes an agreement or stays a communiqué.

Alongside the red lines, Tianjiao Jiang proposes a direct line of communication for AI-related incidents. The scenario is specific: a defensive AI system reacts automatically to activity it reads as suspicious, and the other side reads the reaction as an attack. A direct line would let a government explain quickly that what just happened was an accident, before the misreading compounds.

None of this is new as a demand. The National Security Commission on Artificial Intelligence called for preserving human control over nuclear weapons back in 2021. Five years on there are still no binding mechanisms to enforce it — which is the useful measure of what a document like this one is worth.

The hotline idea has a sharper problem, and it comes from one of the skeptics. Carla Freeman of Johns Hopkins University doubts such channels work at all, and points to the 2023 crisis over the Chinese surveillance balloon, when China did not pick up the phone to Washington. The proposal asks for a new emergency channel on the strength of a precedent in which the existing one went unanswered during the exact kind of ambiguous incident it was built for. A channel is only as good as the political decision to use it, and that decision gets made under precisely the conditions — suspicion, domestic pressure, incomplete information — that argue for not picking up.

What is notably absent is verification. Every one of the four red lines is a statement about the internal architecture of the other country's most secret systems, and the recommendations offer no way for either side to check the other's compliance, or even to define what evidence of compliance would look like. Nuclear arms control historically ran on counting things: warheads, launchers, silos, inspections. Software that decides is not countable. This reads less like an arms control proposal than like an attempt to establish a norm early enough that violating it carries a cost — which is a reasonable goal, but a different one, and worth naming as such.

There is a tension inside the proposal that its authors do not resolve. The hotline scenario presupposes defensive AI systems already reacting on their own to suspicious activity — that is the premise the whole mechanism is built on. If that premise holds, the red lines are being drawn around capabilities that are already in place, and the hotline exists to manage the accidents rather than to prevent the architecture. An agreement written before a weapon exists is arms control. One written after it is already reacting is incident management with better branding.