The old nightmare was straightforward enough to draw on a classroom chalkboard. One side detects missiles. Leaders have minutes to decide whether the warning is real. A hotline exists because the worst possible misunderstanding cannot be allowed to mature in silence.

Artificial intelligence makes the picture messier.

U.S. and Chinese security experts participating in an ongoing dialogue convened by the Brookings Institution and Tsinghua University's Center for International Security and Strategy are proposing a set of safeguards for military AI that borrow heavily from the logic of nuclear risk reduction. Their recommendations include red lines around nuclear command systems, human control over consequential cyber operations, a shared definition of meaningful human control and a dedicated military hotline for emergencies involving autonomous AI.

Neither government has publicly adopted the complete package. That matters. This is a proposal from experts involved in a long-running Track II dialogue, not a signed treaty and not an operational bilateral agreement. But the fact that the proposal exists tells us where the problem has moved.

The military-AI debate is no longer only about whether a drone can identify a target or whether a machine should be allowed to pull a trigger. It is increasingly about whether automated systems can create strategic effects before political leaders even know that an interaction has begun.

That is a different class of danger.

Imagine a defensive AI watching traffic around a nuclear command network. It detects something anomalous and automatically isolates systems, reroutes communications or launches a cyber countermeasure. The other side sees the countermeasure and interprets it as an intrusion. Its own automated defenses respond. Neither country's leadership ordered an attack, but both now possess evidence that looks very much like one.

The machines have not become generals. The crisis has simply outrun attribution.

Speed can make “human control” ceremonial.

Military organizations already talk about keeping a human in the loop. The phrase sounds reassuring because it conjures an image of an operator sitting behind a screen with a large red veto button and enough time to think.

That image is becoming less reliable.

Tianjiao Jiang of Fudan University, one of the authors of the Brookings dialogue material, argues that AI-enabled cyber exchanges can unfold so quickly that the final human decision may exceed physiological limits. His warning goes directly to the weakest version of human oversight: technically retaining a person in the chain while compressing the decision window until the person can do little more than approve what the machine already selected.

A meaningful control is not meaningful because a human name appears somewhere on the workflow diagram. The human needs enough information, authority and time to understand the action being proposed and to stop it before the effect occurs.

That requirement becomes particularly difficult in cyber operations. Attribution is already slow and uncertain. A state may observe malicious traffic without immediately knowing whether it originated from a government unit, a contractor, a criminal group, a compromised civilian system, an autonomous agent or somebody deliberately trying to impersonate one of those actors. AI can accelerate reconnaissance, adaptation and response while leaving the attribution problem exactly as ugly as it was before.

So the faster the automated system becomes, the more likely it is that leaders will inherit a completed sequence instead of an intelligible choice.

This is why the Brookings-Tsinghua proposal reaches beyond the obvious boundary that humans should retain authority over nuclear weapons. The authors argue for red lines preventing AI from autonomously initiating cyberattacks against nuclear command, control and communications systems and other strategically important infrastructure. They also point toward finance, healthcare, energy and other sectors whose disruption could generate pressure for military retaliation.

The logic is simple: some actions are dangerous not because of the code used to perform them, but because of the political meaning the target may assign to them.

A hotline is really an intent channel.

The proposed dedicated military hotline for AI incidents sounds almost embarrassingly analog next to autonomous cyber systems and machine-speed decision loops. Good. Some problems survive modernization because they are human problems underneath.

A hotline is useful when one government needs to communicate intent faster than sensors and analysts can infer it. An unusual automated operation might be accidental, unauthorized, compromised, still under investigation or deliberately initiated by a nonstate actor. The target state may not know which explanation is true. The state responsible for the affected system may not know either.

Being able to say, immediately, “we are seeing this too, it was not authorized, do not treat it as a policy decision while we contain it” could matter more than another layer of machine classification.

That does not make the proposal magically reliable.

Existing U.S.-China crisis communication has failed under pressure before. Reuters notes that experts have questioned the practical value of existing military hotlines, including after Chinese officials did not answer U.S. counterparts during the 2023 balloon incident. Institutional hierarchy can also slow communication because lower-level officials may lack authority to speak before senior political leadership has settled on a response.

An AI hotline therefore has the same uncomfortable dependency as every other hotline: somebody has to answer it, and the person answering needs permission to say something useful.

That is not a reason to dismiss the idea. It is a reason to design the political process around the technical speed of the systems being managed.

The real problem is interpretation under compression.

The public imagination tends to leap toward autonomous weapons because a machine physically firing something is easy to visualize. Strategic instability can emerge much earlier in the chain.

An AI system may rank intelligence reports. Another may prioritize missile warnings. Another may manage network defense. Another may recommend cyber responses. Another may route communications after detecting compromise. None of those systems needs authority to launch a nuclear weapon to influence the conditions under which a human later decides whether one should be used.

That makes the architecture surrounding decision-making as important as the final authorization step.

One system can create false confidence. Another can hide uncertainty behind a probability score. A defensive agent can take an action that an adversary interprets offensively. An operator can receive a machine recommendation under time pressure and assume the machine has already resolved ambiguities that remain very much alive. Multiple individually rational automation layers can combine into a crisis nobody designed.

This is the military version of a failure Cyberdelia keeps finding elsewhere: local optimization is not system safety.

The Brookings dialogue also raises the problem of language. Both sides can endorse “meaningful human control” while implementing completely different systems. One military might require human authorization for every consequential action. Another might allow a human commander to approve a mission envelope inside which an AI chooses targets, routes and timing. Both can point at a human and say the system remains controlled.

A phrase without operational definition is diplomatic wallpaper.

If the two governments ever turn these proposals into real safeguards, the useful work will begin where the slogans stop. What exactly must a human authorize? Which systems are off-limits to autonomous cyber action? How quickly must an AI incident be reported? What evidence should be exchanged without exposing classified capabilities? What happens when one side claims an incident was accidental and the other side does not believe it? What actions automatically suspend machine autonomy during a crisis?

Those questions are ugly because they involve trust between strategic competitors who do not particularly trust each other. Unfortunately, mistrust is exactly why crisis mechanisms exist.

CYBERDELIA ASSESSMENT

The strongest case for military-AI safeguards is not a speculative story about a machine deciding to start World War III. It is the much more ordinary risk that automated systems produce ambiguous strategic effects faster than governments can attribute, explain or reverse them. Red lines around nuclear command systems, operational definitions of human control and a dedicated crisis channel would not eliminate that danger. They would create friction against the most dangerous failure mode: mistaking machine behavior for deliberate national intent.

There is a strange symmetry here. Artificial intelligence is supposed to make military systems faster, more adaptive and more capable of acting under uncertainty. Strategic stability sometimes requires the opposite: delay, confirmation, redundant communication and enough human hesitation to discover that the first interpretation was wrong.

Speed wins contests. It can also close doors.

The most important safety feature in a machine-speed crisis may turn out to be a human being on the other end of a line saying, very clearly, that the machine did not have permission to speak for the country.

News DeskResearch DeskFeatures