Red Lines for the Machine Age: US and Chinese Experts Propose Nuclear-Style Safeguards for Military AI
Ahead of a Trump-Xi summit, Brookings' Melanie Sisson and Fudan's Tianjiao Jiang jointly propose AI red lines around nuclear command systems, a shared definition of 'meaningful human control', and a dedicated military hotline for AI incidents.
An AI system that interferes with a nuclear command network, or launches a military cyber operation at machine speed, could leave Washington or Beijing with only minutes to decide whether the other government has started a war. That is the scenario that security experts from the United States and China are now trying to head off with an unusually concrete set of proposals — nuclear-style safeguards for military artificial intelligence, published this week and picked up by Reuters on September 17, just one week before Presidents Donald Trump and Xi Jinping meet at the White House.
The recommendations come from an ongoing Track II dialogue on AI and national security convened by the Brookings Institution’s Foreign Policy program and Tsinghua University’s Center for International Security and Strategy, with support from the Minderoo Foundation. The dialogue has been running since 2019, and its latest output — a paired set of essays by Melanie W. Sisson, a senior fellow at Brookings’ Strobe Talbott Center, and Tianjiao Jiang, an associate professor at Fudan University’s Development Institute, published September 9 — reads less like an academic exercise and more like a draft agenda for the government-level AI talks both countries are preparing.
What the two sides are proposing
The proposals, developed through bilateral track-two exchanges designed to inform official policy, center on three practical mechanisms.
First, explicit red lines around nuclear systems. Jiang proposes clearly prohibiting AI from autonomously deciding to use nuclear weapons or autonomously attacking nuclear command, control, and communications networks (NC3). Beyond NC3, the experts call for a defined list of critical infrastructure sectors — energy, finance, health care — where autonomous AI attacks would be off-limits, with boundaries clearly drawn in advance.
Second, human-only authority over consequential cyberattacks. Sisson’s essay argues that Trump and Xi should agree that only humans, not AI, should make the decision to initiate a cyberattack against each other’s NC3 or critical infrastructure. The logic extends the 2024 Biden-Xi principle — that humans should retain control over decisions to use nuclear weapons — to the cyber domain, where attacks can unfold in milliseconds. As Sisson frames it, attacks with strategic effects must express human intent and remain subject to human accountability, a narrow point that does not require either capital to agree on broader cybersecurity principles.
Third, a dedicated US-China military hotline for AI incidents. Jiang proposes building on existing channels — the defense minister hotline and the Maritime Military Security Consultation Mechanism — to add a dedicated line for reporting emergency incidents triggered by AI errors or AI cyberattacks. The 2023 balloon incident, he writes, should serve as a wake-up call: without a hotline mechanism, AI-driven drones and unmanned vessels are highly likely to trigger more accidental escalations in the future.
The speed problem at the core
What gives the proposals urgency is a mismatch between machine speed and human physiology. Jiang’s essay is blunt about what he calls the “speed dilemma”: with AI agents, cyberattacks unfold at unprecedented pace, and AI-powered defenses can automatically trigger countermeasures. In one described scenario, an AI detects abnormal traffic targeting an NC3 system and automatically disconnects the network or launches countermeasures; the other side interprets this defensive reflex as a cyber intrusion, and the two sides’ AI systems settle into a mode of “automatic confrontation.” In such ultra-high-speed engagements, Jiang warns, the “final human decision” is likely to exceed physiological limits — meaning the safeguard of human approval quietly becomes fictional.
Attribution compounds the problem. Cyberattacks are notoriously hard to trace, and critical infrastructure can be targeted by states, by non-state actors such as hacker groups or terrorists, or even by AI agents themselves. If an AI-powered attack hits a hospital grid, how do governments determine whether it was authorized — or whether someone deliberately framed a state actor to provoke conflict? Without reliable attribution, human accountability cannot be established, and retaliation risks triggering the very unintended escalation the safeguards exist to prevent.
Why “meaningful human control” needs a definition
The most quietly ambitious proposal is definitional. Both governments say they believe in “human control” over military AI, but Jiang and Sisson warn that the two countries may be using identical language to justify different levels of machine autonomy. Jiang’s essay reaches back to Chinese Premier Zhou Enlai’s demand for “absolute certainty” (萬無一失) in China’s nuclear testing program as an embodiment of the human-control principle, while the American strand of the debate descends from Air Force Colonel John Boyd’s OODA loop. Given fundamentally different institutional frameworks and strategic cultures, the experts propose regular dialogue — or a standing terminology working group — to ensure mutual acceptance of each other’s definitions of “meaningful human control” and related safeguard mechanisms.
This matters because a definition is what turns a principle into something verifiable. The 2024 leader-level commitment on nuclear weapons was widely welcomed but stayed declaratory. Translation into “actionable institutional arrangements,” as Jiang puts it, is where the process has historically stalled.
The obstacles are structural
Formal adoption by both capitals remains slow, and the essays do not shy away from why. Washington has no single arms-control home for AI: national security policy is spread across the White House National Security Council, the State Department, the Pentagon and other agencies. Beijing, by contrast, has integrated AI concerns into its formal arms-control bureaucracy, but the American side worries that China’s centralized approach is easier to redirect.
Both governments also remain wary of measures that could slow their own technological development. Trump has warned that broad restraints could hand China an advantage, while Beijing views many US technology controls — especially export restrictions on advanced chips — as attempts to preserve American dominance. The opacity of AI technology makes it impossible to accurately assess an adversary’s actual capabilities, or even to distinguish whether a given military AI system is offensive or defensive, feeding a classic security dilemma.
The timing nonetheless favors movement. The proposals were published in anticipation of a forthcoming US-China government-level dialogue on AI, and the September 24 Trump-Xi state dinner — attended, per Bloomberg, by OpenAI’s Sam Altman, Nvidia’s Jensen Huang and Apple’s Tim Cook — puts the two decision-makers in the same room on the eve of expected chip and export-control talks. Reuters separately reported this month that the two countries are planning their first dedicated AI safety talks of Trump’s second term, with Washington seeking joint monitoring of AI-driven cyberattacks.
The precedent worth remembering
Track II dialogues have produced agreements before. The November 2024 Biden-Xi affirmation that humans should retain control over nuclear-use decisions emerged from years of semi-official exchanges much like this one. The new proposals essentially ask both governments to run that playbook again — narrow, specific, leader-level commitments first; verifiable protocols and safeguards afterward.
Sisson argues that leader-level statements are the necessary precondition for bilateral dialogue on verifiable protocols, and also the strongest public signal that both governments understand what is at stake. Jiang, for his part, wants future dialogues to incorporate broader issues, including the regulation of lethal autonomous weapons systems.
The stakes are framed in the essays with unusual directness: the goal is to reduce the risk that AI malfunctions mislead humans — or override human judgment entirely — and push two nuclear powers into a war nobody chose. Whether September 24 produces anything more than a communiqué is uncertain. But for the first time since military AI went from theory to deployed infrastructure, both sides of the Pacific have put specific, negotiable mechanisms on paper — red lines, definitions, and a phone that rings when the machines misbehave.
Sources
- [1] https://www.brookings.edu/articles/advancing-human-control-of-military-ai/
- [2] https://www.reuters.com/world/china/us-china-security-experts-propose-nuclear-style-safeguards-ai-risks-2026-09-17/
- [3] https://www.thenews.com.pk/amp/1416556-us-chinese-security-experts-propose-nuclear-style-safeguards-for-military-ai
- [4] https://www.japantimes.co.jp/news/2026/09/17/world/politics/us-china-nuclear-ai-safeguards/