Skip to content
AI.info

The Pulse

US and China Experts Set Red Lines for Military AI

Experts from Brookings and Tsinghua propose human control over AI-enabled cyberattacks, restrictions around nuclear systems, and a US-China military hotline. The recommendations arrive before planned government-level AI talks and a Septembe

US and China Experts Set Red Lines for Military AI

AI.info Team ·

American and Chinese security experts are urging Washington and Beijing to keep artificial intelligence away from the decisions most likely to trigger a military crisis: launching nuclear weapons, attacking nuclear command networks and initiating high-impact cyber operations.

The recommendations, published by the Brookings Institution on September 9, call for explicit red lines around military AI, a shared definition of “meaningful human control” and a dedicated US-China hotline for AI-related incidents. Reuters reported the proposals on September 17, ahead of planned government-level AI talks and an expected September 24 meeting in Washington between President Donald Trump and Chinese President Xi Jinping.

The proposals do not represent an agreement between the two governments. They come from a Track II dialogue involving experts associated with Brookings and Tsinghua University’s Center for International Security and Strategy, a forum that has operated since 2019.

From nuclear launch decisions to cyberattacks

Melanie Sisson, a senior fellow at Brookings, argues that the principle already accepted for nuclear weapons should extend to cyber operations capable of producing strategic effects. Humans, rather than AI systems, should retain sole authority to initiate attacks against an opponent’s nuclear command, control and communications systems, known as NC3, or against strategically important infrastructure.

“The United States and China have not developed a common approach to governing AI in the military domain.”

Melanie W. Sisson, Brookings Institution

An autonomous system could malfunction, exceed its instructions or be compromised. A country facing an unexplained intrusion might have only minutes to decide whether the event was an accident, an unauthorized operation or an attack ordered by the other government.

That uncertainty is especially dangerous around NC3 networks, which support the detection of threats, the transmission of orders and the control of nuclear forces. A cyber operation that disrupts those systems could be interpreted as preparation for a wider attack even if no government intended it that way.

Jiang’s three safeguards for military AI

Tianjiao Jiang, an associate professor at Fudan University, proposes three practical steps. The first is a list of prohibited actions, including any AI system independently deciding to use nuclear weapons or autonomously attacking nuclear command systems. Jiang also identifies energy, finance and healthcare as sectors where the two countries could define limits on autonomous offensive operations.

The second step is a shared definition of “meaningful human control.” Both governments already use language about human oversight, but the experts warn that identical terms could conceal very different levels of machine authority. A terminology working group or regular bilateral dialogue could help establish whether a human has genuinely reviewed and authorized an action rather than simply approving a recommendation after the system has done the substantive work.

The third proposal is a dedicated military hotline for incidents involving AI. Jiang argues that automated cyber defenses could respond to suspicious activity before commanders understand what happened, creating a chain of actions that moves faster than human decision-making.

A direct channel would give either side a way to report that an operation was accidental, unauthorized or still under investigation. The aim would be to prevent a technical incident from being treated immediately as a deliberate act of war.

The hotline problem is already visible

Existing communication arrangements offer a warning about the limits of formal channels. Carla Freeman of Johns Hopkins School of Advanced International Studies has questioned the usefulness of the current US-China military crisis hotline, citing Chinese officials’ refusal to answer US calls during the February 2023 spy-balloon incident.

In an article for War on the Rocks, Freeman wrote: “No one in the Chinese system wants to communicate with the United States until the top leadership in consultation with relevant actors within China’s party-state have decided on a response, which may take days if not longer.”

That concern applies directly to AI incidents. A hotline can reduce delay only if officials have permission to use it, know which events require contact and trust that early communication will not be treated as an admission of wrongdoing.

Beijing has an arms-control office for AI; Washington does not

China has placed military AI within the portfolio of its Foreign Ministry’s Department of Arms Control, which also handles nuclear weapons, non-proliferation, missiles and related international security issues. At a United Nations meeting in Geneva in June, China’s ambassador for disarmament affairs, Shen Jian, said military AI could affect strategic stability and increase the risks of miscalculation and escalation. He also said weapons should remain under human control.

Washington has no single arms-control office responsible for AI. Policy is divided among the White House National Security Council, the State Department, the Pentagon and other agencies, creating a more fragmented structure for bilateral discussions.

Neither government has publicly endorsed the Brookings-Tsinghua recommendations. Both also remain wary of rules that could slow military or commercial development. President Trump has warned that broad restrictions could give China an advantage, while Beijing portrays many US technology controls as efforts to preserve American dominance.

A narrow agreement faces a wider rivalry

The experts’ proposal focuses on a narrow point of agreement rather than a general settlement over military AI. It does not require Washington and Beijing to share views on cybersecurity, export controls or the broader use of autonomous systems. Instead, it asks both sides to accept that certain decisions should express clear human intent and accountability.

The proposal builds on the commitment reached by then-President Joe Biden and Xi Jinping in November 2024 that humans should retain control over decisions to use nuclear weapons. Extending that principle to cyberattacks against nuclear systems would give the earlier statement a practical boundary beyond the nuclear launch decision itself.

Government-level discussions will determine whether the recommendations move beyond expert dialogue. For now, the concrete agenda is three parts: prohibit autonomous attacks on nuclear systems, define meaningful human control and create a channel that officials can use before an AI incident becomes a military confrontation.

Source

Brookings Institution

Explore

More articles