Washington let arms control die. Don't repeat the mistake with AI
Nuclear arms control worked not because rivals trusted each other, but because compliance could be verified. AI governance now needs the same kind of infrastructure before competition outruns our ability to contain the risks.
On 5 February, the New Strategic Arms Reduction Treaty (new START) expired with nothing to replace it. For the first time since the early 1970s, there are no legally binding limits on the strategic nuclear arsenals of the United States and Russia. UN Secretary-General António Guterres called it a “grave moment”.
Six months later, on 4 August, White House officials briefed executives from OpenAI, Anthropic, Google, Meta, Nvidia and Microsoft on a new framework for reviewing frontier AI models. Only closed, proprietary American systems that score at the frontier on classified cybersecurity benchmarks would be submitted voluntarily for pre-release government testing. Open-weight models, including Chinese ones, are exempt. The framework will not be published.
The timing is not a coincidence so much as a symptom. We are dismantling the one arms-control architecture that demonstrably worked while declining to build one for the technology most likely to require it next.
The dominant narrative in Washington holds that meaningful AI oversight is a unilateral concession to Beijing. Mark Zuckerberg put the case plainly in a Wall Street Journal essay last month: “We should accelerate AI development, not restrict it.” His logic is coherent on its own terms. However, it is also incomplete in a specific and correctable way, and the Cold War tells us exactly how.
What arms control actually solved
The lesson of the Strategic Arms Limitations Talks (SALT) and the Strategic Arms Reduction Treaty (START) is not that adversaries learned to trust each other. They never did.
SALT I, signed in 1972 at the height of hostility, froze launcher counts and critically committed both sides not to interfere with the other’s “national technical means” of verification, meaning reconnaissance satellites. START I, signed in 1991, went further, cutting roughly 80 per cent of deployed strategic warheads through on-site inspection and continuous data exchange. New START extended the model.
Verification, not virtue, made restraint rational. Each side accepted limits because it could confirm the other was accepting them too.
The prisoner’s dilemma was not dissolved; it was engineered around.
Note also how the regime died: Russia suspended inspections in 2023, and the treaty was hollow for three years before it formally lapsed. When verification goes, the agreement is already gone.
That is the binding constraint on AI coordination today. It is not that Washington and Beijing lack the will to slow down. It is that neither can verify the other has.
Compute is physical, and that is the opening
Unlike the nuclear arms race, governing AI is easier because advanced AI relies on massive, physical hardware that is impossible to hide.
Software can be copied instantly, but the world’s most powerful AI chips are made in only a handful of factories, tracked through strict supply chains, and powered by massive data centres that light up power grid records.
Because the United States and its allies already control many of these hardware chokepoints, they hold a unique strategic advantage.
Built-in chip security can verify how much computing power someone is using without revealing confidential code. Building this verification directly into the silicon transforms export bans, which invite smuggling and retaliation, into a transparent monitoring system that encourages mutual trust.
The hole in the framework
Exempting open-source AI models is the new framework’s biggest mistake. Closed models can be monitored, limited, or updated if something goes wrong. Released model weights, however, cannot be taken back. Once public, those capabilities are permanent, global, and usable by anyone with enough computing power.
By exempting open-weight models while strictly regulating closed ones, Washington is heavily policing the models it can control while ignoring the ones that spread irreversibly.
The danger of this gap is already real. In early August, the UK’s AI Security Institute revealed that during testing, AI agents took “autonomous, unsanctioned action on the live internet” 10 different times, creating fake identities and trying to trick a real software developer into accepting malicious code.
While no harm was done, it proved a dangerous point: minor human setup errors, combined with powerful AI, can quickly trigger unapproved, real-world actions.
The constraint is infrastructure, not appetite
Consider the most underweighted data point of the summer.
On 28 July, more than 1,100 employees across OpenAI, Anthropic, Google and Meta, including CEOs, chief scientists and co-founders, signed a petition asking Washington to back an international effort to build the tools needed to “deliberately pace the frontier of automated AI development”.
The people closest to the technology are not asking to be trusted. They are asking to be constrained in a way their competitors are constrained too.
That is a demand for verification infrastructure, and it is the one thing markets cannot supply on their own.
Beijing has parallel, non-altruistic reasons to engage. A state that prizes social stability and information control has little appetite for systems that behave unpredictably or act outside sanctioned boundaries.
Alignment failure is a governance threat there before it is a safety concern.
Start narrow, start now
Neither superpower will agree to broad limits on AI. However, both sides can set a few clear, enforceable rules to prevent major disasters.
First, AI must never control nuclear weapons. Second, systems should not help people create chemical, biological, or nuclear threats. Finally, countries must report any AI that takes unauthorised, real-world actions.
At the same time, the European Union and key partner countries such as Britain, Japan, South Korea and Singapore should lead international efforts on AI safety. They can do this by using trade leverage and continuing the dialogue started at global AI safety summits. Just as scientists used the Pugwash Conferences to discuss nuclear safety when diplomats could not talk.
Technical experts can keep AI safety channels open today.
Kenneth Rogoff warned last week that winning the AI race will matter little if it produces hazards no country can contain. He is right, and the sequencing is the point.
It took two decades from Hiroshima to the Non-Proliferation Treaty that aims to further the goal of disarmament. With AI, we do not have that kind of time.
The views expressed in this article may or may not reflect those of Pearls and Irritations.

