U.S. and Chinese security experts are urging Washington and Beijing to establish safeguards for military artificial intelligence, warning that autonomous systems could trigger dangerous escalation if they interfere with nuclear command networks or conduct cyber operations without clear human authorization.
The recommendations include restrictions on AI activity around nuclear systems, continued human control over consequential cyberattacks and a dedicated hotline for incidents involving autonomous military systems.
The proposals were published ahead of planned government level discussions on artificial intelligence and an expected September 24 meeting in Washington between U.S. President Donald Trump and Chinese President Xi Jinping.
The recommendations came from Melanie Sisson, a senior fellow at the Brookings Institution, and Tianjiao Jiang, an associate professor at Fudan University. Both participated in a U.S. China AI and national security dialogue convened since 2019 by Brookings and Tsinghua University’s Center for International Security and Strategy.
Stay ahead of the geopolitical week.
MD Briefing delivers expert analysis across five global fronts — the Indo-Pacific, energy, geoeconomics, European security, and the Middle East — every Monday morning. Free.
Their work reflects an expanding focus in the U.S. China AI rivalry. Competition has largely centered on advanced chips, computing capacity and increasingly capable AI models, but security experts are now examining problems more commonly associated with nuclear arms control, including accidental escalation, machine driven military decisions and communication between nuclear armed states during crises.
Keeping AI away from nuclear decisions
Sisson argued that humans should retain sole authority to initiate AI enabled cyberattacks against another country’s nuclear command, control and communications systems or strategically important infrastructure.
The concern is that an autonomous system could malfunction, exceed its instructions or be compromised. A government on the receiving end of such an attack could then have only a short period to determine whether the incident was accidental, unauthorized or deliberately ordered by the other country.
Jiang proposed explicit restrictions preventing AI systems from independently deciding to use nuclear weapons or autonomously attacking nuclear command systems. He also proposed safeguards covering critical infrastructure such as energy, financial systems and healthcare.
Jiang called for a shared definition of “meaningful human control” so that Washington and Beijing do not use the same terminology while applying fundamentally different standards to the degree of autonomy permitted to military systems.
The proposal builds on a principle endorsed by former U.S. President Joe Biden and Xi in November 2024 that humans should retain control over decisions involving the use of nuclear weapons.
Lora Saalman, an associate senior fellow at the Stockholm International Peace Research Institute, wrote in February that the principle represented an area of U.S. China convergence even as both countries appeared to be incorporating AI more deeply into nuclear and nuclear related systems.
When AI decisions move faster than governments
Jiang also proposed establishing a dedicated U.S. China military hotline for incidents involving autonomous AI.
The concern is that automated systems could respond to one another faster than human officials could determine what was happening. A defensive AI system could interpret suspicious activity as an attack and automatically respond, while the other side could interpret that response as evidence of hostile action and retaliate.
A direct communication channel could give governments an opportunity to clarify whether an unusual AI operation was accidental, unauthorized or still under investigation before it was interpreted as a deliberate attack.
The proposal faces questions about whether existing communication mechanisms would be sufficient.
Carla Freeman of Johns Hopkins School of Advanced International Studies has previously questioned the effectiveness of the existing U.S. China military crisis communication hotline. She pointed to China’s decision not to answer U.S. calls during the February 2023 spy balloon incident.
Freeman has also argued that China’s centralized bureaucratic structure can make it difficult for lower ranking military officers to respond independently during encounters with U.S. counterparts.
Washington and Beijing weigh AI security
Neither the United States nor China has publicly endorsed the Brookings Tsinghua recommendations. China, however, has increasingly incorporated military AI into its existing arms control framework.
AI falls within the portfolio of China’s Foreign Ministry Department of Arms Control, which also deals with nuclear weapons, non proliferation, missiles and other international security issues.
Shen Jian, China’s ambassador for disarmament affairs, told a U.N. meeting in Geneva in June that military AI could affect strategic stability and increase the risks of miscalculation and conflict escalation. He also said weapons should remain under human control.
At the same time, Beijing has argued that concerns about AI safety should not be used to justify technological restrictions.
The United States has no single government institution responsible for AI within the arms control framework. Related national security issues are handled across agencies including the White House National Security Council, State Department and Pentagon.
Both governments also remain cautious about measures that could constrain their own technological development.
Trump has warned that broad restrictions on AI could give China an advantage, while Beijing has characterized several U.S. technology controls as efforts to maintain American technological dominance.
The emerging debate therefore involves two parallel concerns: limiting the risks posed by increasingly autonomous military AI while preserving the technological capabilities that Washington and Beijing regard as important to national security.
The challenge for both sides will be determining how much human control and communication is necessary to prevent AI driven incidents from escalating, without creating restrictions that either government considers incompatible with its broader security and technological objectives.
With information from Reuters.

