- A long-running US-China expert dialogue convened by Brookings and Tsinghua University proposed nuclear-style safeguards for military AI, published days before a September 24 Trump-Xi meeting in Washington.
- The core recommendations are narrow and concrete: keep humans in sole control of nuclear launch decisions, build a dedicated hotline for AI incidents, and agree on a shared definition of meaningful human control.
- The unresolved problem is definitional. Both governments can adopt the same phrase, meaningful human control, while permitting very different levels of machine autonomy underneath it.
A 2019 dialogue quietly wrote arms-control rules for military AI
The recommendations came not from either government but from a track-two channel that has outlasted three years of open hostility between the two capitals. Since 2019, the Brookings Institution and Tsinghua University's Center for International Security and Strategy have convened a US-China dialogue on AI and national security. Its latest output, led by Brookings senior fellow Melanie Sisson and Fudan University's Tianjiao Jiang, reads less like a think-tank paper and more like the opening draft of an arms-control regime, as first reported by Reuters.
Three ideas anchor it. First, a red line around nuclear systems: humans, not models, must retain sole authority to initiate an AI-enabled cyberattack on nuclear command infrastructure. Second, a dedicated US-China hotline built specifically for AI incidents, separate from existing military channels. Third, and hardest, a shared definition of meaningful human control. The timing is deliberate. The proposals landed ahead of an expected September 24 meeting in Washington between Presidents Trump and Xi, the first substantive opening in months for the two sides to put anything about AI on the table.
| Convened by | Brookings Institution and Tsinghua University's Center for International Security and Strategy, since 2019 |
| Authors | Melanie Sisson (Brookings) and Tianjiao Jiang (Fudan University) |
| Nuclear red line | Humans keep sole authority over AI-enabled attacks on nuclear command systems |
| Hotline | A dedicated US-China channel for AI incidents |
| Definition | A shared meaning for "meaningful human control" |
| Context | Ahead of a September 24 Trump-Xi meeting in Washington |
Why meaningful human control is the hardest clause to sign
The phrase sounds like agreement. It is closer to a trap. As Jiang warned, both countries can use identical language to justify different levels of machine autonomy. One side can call a human who approves a target list every morning meaningful control. The other can reserve the term for a human who authorizes each individual strike. The words match, the systems do not, and each side walks away believing it has conceded nothing.
Both governments can sign the same three words, meaningful human control, and each walk away having conceded nothing.
This is the same fault line that made early nuclear treaties so slow. Verification, not intent, is what makes a red line real. A ban on autonomous nuclear launch means little without a shared way to confirm that a human sits in the loop, and neither Washington nor Beijing has an inspection regime for software that updates weekly. The value of the dialogue is that it names the definitional gap early, before a crisis forces both sides to discover it under time pressure.
The escalation math that makes a hotline necessary
The hotline recommendation is the most immediately practical, because it answers a specific fear. In a fast cyber exchange between two automated defense systems, escalation can run faster than humans can intervene. A model on one side flags an intrusion, responds, and triggers a counter-response on the other, all in the seconds before a duty officer even sees an alert. The traditional leader-to-leader hotline, built for a world where decisions took hours, is too slow for that loop.
An AI-specific channel does not stop the machines. It buys back the minutes needed to ask whether an exchange was an attack or a malfunction. That distinction, attack versus error, is exactly what automation erodes, because a system optimized to respond quickly has no incentive to pause and check which one it is looking at.
What a Trump-Xi handshake would and would not lock in
Even a warm summit would not turn these ideas into binding policy. This is a track-two proposal, and its authors know it. What a handshake could do is legitimize the vocabulary, signal to both militaries that AI risk is now a head-of-state topic, and create cover for the working-level talks where real definitions get negotiated. That is not nothing. Most arms-control regimes began as unofficial papers that governments later chose to adopt, a pattern visible in the way labs and states are now converging on shared AI standards.
The deeper message for the AI industry is that military and civilian AI governance are converging. The same questions labs debate about autonomy, oversight, and control are now being asked about weapons, by people who can turn an ambiguous definition into a strategic miscalculation. Domestic efforts like the Senate's push to police frontier models are one track. This is the other, and it moves at the speed of geopolitics.
The first draft of the rules exists. Whether either government signs its name to them, and agrees on what the words mean, is the harder task that a September handshake would only begin.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.