Skip to main content

Military AI Control and the Verification Gap

Picture

Member for

1 year 3 months
Real name
The Economy Editorial Board
Bio
The Economy Editorial Board oversees the analytical direction, research standards, and thematic focus of The Economy. The Board is responsible for maintaining methodological rigor, editorial independence, and clarity in the publication’s coverage of global economic, financial, and technological developments.

Working across research, policy, and data-driven analysis, the Editorial Board ensures that published pieces reflect a consistent institutional perspective grounded in quantitative reasoning and long-term structural assessment.

Modified

Military AI cannot be verified or controlled like nuclear arms
Washington and Beijing's summit will restate intent, not create enforcement
Only a middle-power coalition could impose real compliance costs

On September 24, 2026, Chinese President Xi Jinping visits the White House for the second time in four months, and military artificial intelligence is rapidly rising on the agenda of the two leaders, alongside trade, Taiwan and the war in Iran. As early as November 2024, Washington and Beijing had agreed that decisions to use nuclear weapons should remain in the hands of humans. The question today is whether this principle can be extended to the entire spectrum of military AI, from targeting systems to autonomous cyber operations. The recent analysis by the Brookings Institution, from American and Chinese perspectives, does not provide a reassuring answer. Controlling military AI remains, for now, a political commitment without an enforcement mechanism, and the upcoming summit will hardly bridge this gap.

Controlling Military AI as a Political Commitment

The Brookings proposal starts from a common base: neither side should allow autonomous systems to launch cyberattacks against nuclear command systems or critical infrastructure. Sisson adds specific red lines; Jiang proposes a dedicated hotline for AI incidents and a common definition of "meaningful human control." The problem lies not in the intent of these proposals, but in what they leave open: which human approves what action, with how much time, and how compliance could ever be verified within classified military networks. The same dilemma appears in the National Security Presidential Memorandum NSPM-11, which simultaneously requires human accountability in the chain of command and rapid military dominance through artificial intelligence, two goals that tend to negate each other.

The same hesitation appears outside the military sphere. Anthropic recently published an essay in favor of slowing down the development of advanced models, while acknowledging that a unilateral U.S. slowdown would leave China to fill the gap. The exact same argument keeps Washington and Beijing committed to a parallel acceleration of military AI, even as both sides declare a commitment to human control. AI is fundamentally different from the nuclear weapons that inspired these commitments. It is software, it is copied, it is integrated into systems that are already in operation, and it leaves no trace left by missile tests or enrichment facilities. No state can see the training data or the architecture of the adversary's models, and even access to computing power is only seen indirectly, through energy consumption and supply chains. With no physical object to measure, verification loses the ground on which nuclear arms control has rested for seven decades.

Figure 1: The U.S. and China alone account for nearly half of world military spending.

How AI Already Works in the Field

Integration is no longer experimental. Military Review has described the phenomenon as "command without control": power formally remains in the hands of humans, but the judgment that gives it meaning is gradually emptied of content, replaced by systems optimized for speed. Systems like the Maven Smart System and TITAN process data at a scale impossible for human teams, while war game experiments at the Army War College recorded officers sticking to AI suggestions even after they were proven incorrect, a phenomenon that researchers call cognitive anchoring. In the U.S.-Israeli campaign against Iran, AI systems generated over a thousand targets within twenty-four hours, compressing the personalized assessment into a sample check without any formal rules having changed. The same compression is evident in the controversy surrounding the integration of the Claude model into Palantir's Maven system, where the question was not whether the model worked technically correctly, but whether it left enough room for the human judgment that the company itself claims to preserve.

The asymmetry doesn't stop there. According to a senior Pentagon official, even close U.S. allies lack the computing infrastructure or skilled technicians to keep up with the pace, while South Korea remains the partial exception without closing the scale gap. The ICRC identifies four distinct areas of military use: intelligence and surveillance, cyber operations, autonomous weapons, and command decisions, each carrying a different kind of risk. In intelligence, it is the overestimation of accuracy. In cyber operations, it is speed that exceeds any human reaction time. In autonomous weapons, it is the distinction between target and non-target. In command decisions, it is the gradual shift of responsibility from human to system. This complexity makes it more difficult to attempt to build a broader, multilateral control regime, since the ability to integrate such systems remains the prerogative of a few states. The result is a field where regulation, if it ever arises, will be shaped almost exclusively by the two forces that have the greatest ability to circumvent it.

Why the Nuclear Parallel Fails

Analysis from Johns Hopkins SAIS pinpoints the problem accurately. Nuclear deterrence worked because weapons were physical objects with slowly changing capabilities, and because mutually assured destruction created costs so certain that restraint became rational without an external enforcer. Military AI reverses all three conditions. Shanahan parallels the current situation to the "missile gap" of the 1950s, when the belief that Washington was lagging behind Moscow later proved unfounded, having already triggered a series of armaments decisions. Symmetry of capabilities, when accompanied by an exponential rate of change, is not as reassuring as in classical deterrence theory; it produces equivalent anxiety on both sides, as neither can be sure that the other is not hiding a leap.

Artificial intelligence is also moving at software speed, not at the slow pace of renewal of a nuclear arsenal. The very concept of human control, after all, does not start from a common starting point on both sides: The Brookings analysis traces the root of American thought to the OODA decision loop formulated by John Boyd in the 1970s, while in Chinese military tradition it traces an earlier reference, Zhou Enlai's mandate for absolute certainty in the country's nuclear tests. Project Syndicate warns that without constant dialogue, a return to zero-sum conflict remains an open possibility, while the BBC recently described the competition as a double race, with China leading on the scale of application and the U.S. in cutting-edge models, with neither side being considered firmly ahead. Research by the Middlebury Institute shows that artificial intelligence asymmetrically accelerates propagation technologies over detection technologies, generally strengthening the secret player over the overseer. This difference explains why head counting and satellite surveillance, tools that underpinned nuclear arms control, have no equivalent in the world of software.

Figure 2: Russia and the U.S. hold more than four-fifths of the world's nuclear warheads.

The Role of Middle Powers

If the two superpowers cannot impose restraint on each other, the question shifts to who else could. The European Union already has a regulatory framework through the AI Act, while countries such as South Korea, Japan, Australia, the United Kingdom and Canada could theoretically coordinate in a regime analogous to the Wassenaar Arrangement, adapted to software and computing infrastructure instead of conventional weapons. The goal would not be to bind China through such a mechanism, which the Wassenaar Arrangement itself is unable to achieve for non-participating states, but to create a coalition of markets and supply chains large enough that the non-compliance of any superpower entails real costs of access to marketts, semiconductors and research collaborations. Such a regime would not replace the bilateral negotiation between Washington and Beijing. It would work in parallel, offering the element of external consistency that no bilateral agreement can produce on its own.

The idea is not as unrealistic as it sounds, especially when military spending beyond the two superpowers is increasing at its own pace.

Figure 3: Europe's military spending grew faster than any other region's over the decade.

In the absence of such coordination, what remains possible is narrower: direct lines of communication, accident notification protocols, explicit commitments against autonomous cyberattacks on nuclear infrastructure. This is crisis management, not arms control, a distinction that the rhetoric of "human control" tends to disguise.

The Conclusion Without Illusions

The September 24 summit will likely produce new statements about human control of military artificial intelligence. It will not produce regulation, no matter how sincere the intentions of both sides are. The contradiction between states that commit to keeping humans at the center of decision-making while at the same time developing systems that make them structurally redundant cannot be resolved by diplomatic statements, no matter how often they are repeated. It can only be solved with verification and enforcement tools that do not exist today, and that the international community has not yet seriously begun to construct.

The question that will ultimately determine whether military AI can be curtailed is not whether the U.S. and China will publicly recommit to the principle of human control. They will do so, as they did in November 2024, and will likely repeat it after the September 24 summit. The question is whether any third party, an alliance of middle powers or an expanded regulatory framework, will ever gain the ability to impose real costs on anyone who violates that commitment. Without such a mechanism, each new declaration will repeat the same pattern as the 2024 one, morally weighty but technically unenforceable. Until then, the control of military AI will remain what it is today: an intent without a mechanism.


This article is based on an original research article published by The Economy Research. For the original version, please refer to Military AI Control: Verification and Enforcement Limits.

The views expressed in this article are those of the author(s) and do not necessarily reflect the official position of The Economy or its affiliates.


References

Amodei, D. (2026) Pacing the Frontier. Anthropic Blog.
Bremmer, I. (2026) The AI Race Could Sink US-China Détente. Project Syndicate.
International Committee of the Red Cross (2026) FAQ: Artificial Intelligence (AI) in the Military Domain.
Johns Hopkins School of Advanced International Studies (2026) In AI, The United States and China Are Racing In The Dark.
Mishra, P. (2026) Command Without Control: Mission Command in the Age of Artificial Intelligence. Military Review.
Sisson, M. W. and Jiang, T. (2026) Advancing Human Control of Military AI. Brookings Institution.
The White House (2026) National Security Presidential Memorandum NSPM-11: Artificial Intelligence in the National Security Enterprise.

Picture

Member for

1 year 3 months
Real name
The Economy Editorial Board
Bio
The Economy Editorial Board oversees the analytical direction, research standards, and thematic focus of The Economy. The Board is responsible for maintaining methodological rigor, editorial independence, and clarity in the publication’s coverage of global economic, financial, and technological developments.

Working across research, policy, and data-driven analysis, the Editorial Board ensures that published pieces reflect a consistent institutional perspective grounded in quantitative reasoning and long-term structural assessment.