Security researchers from the United States and China have published a joint policy framework urging Washington and Beijing to establish binding restrictions that prohibit artificial intelligence from independently directing nuclear weapons or strategic cyber warfare. The proposal, released ahead of an upcoming bilateral summit between U.S. President Donald Trump and Chinese President Xi Jinping, warns that automated command systems operating without human oversight could rapidly escalate minor software errors into full-scale international conflicts.
Key points
- Researchers from the Brookings Institution and Fudan University published a proposal urging binding limits on military AI.
- The framework calls for barring AI from initiating nuclear strikes or targeting nuclear command and communications networks.
- The authors recommend creating a dedicated bilateral military hotline to resolve AI malfunctions and false alarms.
- The recommendations arrive ahead of a scheduled Sept. 24 summit between Donald Trump and Xi Jinping in Washington.

As armed forces integrate autonomous algorithms into intelligence, surveillance, and operational planning, the speed of military decision-making increasingly outpaces human oversight. Because automated software reacts in milliseconds, an unverified false alarm or a localized software malfunction could be misinterpreted by an adversary as a deliberate military strike, leaving commanders with little time to de-escalate.
Safeguards for Automated Command Networks
The policy paper, titled “Advancing human control of military AI,” was co-authored by Melanie W. Sisson, a senior fellow at the Brookings Institution, and Tianjiao Jiang, an associate professor at Fudan University. The publication represents the latest initiative from the Track II U.S.-China AI and National Security Dialogue, a project convened since 2019 by Brookings and Tsinghua University’s Center for International Security and Strategy.
The authors argue that the rapid development of agentic systems—software capable of pursuing goals autonomously without step-by-step human prompts—demands formal guardrails similar to Cold War nuclear pacts. Rather than limiting the technical capability of the underlying models, the proposal focuses on governance and command restrictions.
“As militaries integrate agentic AI into their operations and AI models advance rapidly in sophistication and capability, new pathways to catastrophic outcomes are emerging. Presidents Donald Trump and Xi Jinping can lead in governing these dangers by agreeing that only humans, not AI, should make the decision to initiate a cyberattack against each other’s nuclear command, control, and communications systems (NC3) or critical infrastructure.”
Proposed Restrictions for Nuclear and Cyber Operations
The joint paper outlines specific operational boundaries aimed at keeping lethal force under direct, verifiable human authority. The researchers urge Washington and Beijing to establish mutual rules across several key defense sectors:
- Nuclear weapons isolation: Prohibiting autonomous software from authorizing or executing nuclear launches under any circumstances.
- Command network protections: Banning AI-driven cyber operations targeting nuclear command, control, and communications (NC3) infrastructure.
- Critical infrastructure safeguards: Retaining strict human authorization for cyber operations capable of disabling civilian power grids, transportation, or communications networks.
- Bilateral definitions: Establishing a shared, formal diplomatic definition of what constitutes meaningful human control over autonomous systems.
These measures build on an earlier bilateral understanding reached in November 2024, when then-U.S. President Joe Biden and President Xi affirmed that human operators must retain ultimate authority over nuclear launch decisions.
Crisis Hotlines and Communication Roadblocks
To prevent misunderstandings caused by algorithm glitches, the researchers recommend setting up a dedicated military-to-military emergency hotline specifically for artificial intelligence incidents. If an autonomous system behaves erratically, launches an unauthorized process, or suffers a security breach, the channel would provide defense officials with direct access to clarify anomalies before either side orders a retaliatory strike.
Technical hotlines, however, face established diplomatic hurdles. Carla Freeman, an expert at Johns Hopkins University, pointed out that emergency communication channels rely on political willingness to engage quickly. During past disputes, such as the 2023 high-altitude balloon incident, Chinese defense officials delayed responses until political leadership completed extensive internal reviews, consuming days rather than the minutes required during a fast-moving automated crisis.
Diplomatic Hurdles Ahead of the Presidential Summit
Neither government has formally adopted the recommendations into official military policy. Internal bureaucratic differences also complicate negotiations. Beijing manages military AI policies under the arms-control division of its Ministry of Foreign Affairs, while Washington divides AI oversight among the Department of Defense, the State Department, and the National Security Council.
Both governments remain wary of accepting restrictions that might blunt their domestic technical development. Chinese Minister of State Security Chen Yixin previously stated that artificial intelligence “fundamentally transforms the form of military struggle.” How far both administrations are willing to go in codifying restrictions remains unclear ahead of the planned Trump-Xi meeting scheduled for September 24 in Washington.





