“Human control” over military AI needs authority, time and fail-safe tests
US and Chinese experts propose practical safeguards around strategic AI decisions. The value lies in turning a principle into testable controls, while recognising that the proposals are not an adopted agreement.

What happened
Brookings published paired US and Chinese perspectives from a Track II dialogue on maintaining human control over military AI and AI-enabled cyber operations.
Why it matters
A nominal human in the loop is not meaningful if that person lacks verified authority, adequate decision time, reliable information or a working stop mechanism.
Brookings published paired US and Chinese perspectives from a Track II dialogue convened with Tsinghua University’s Center for International Security and Strategy. The authors propose extending human control beyond nuclear-use decisions to AI-enabled cyberattacks affecting nuclear command systems and critical infrastructure, and discuss red lines, shared terminology and a dedicated incident hotline. Reuters independently reported the expert proposals and their relationship to planned government dialogue.
These are expert recommendations, not a treaty or confirmed bilateral policy. Track II participants can explore options without binding either government. The article also presents two perspectives rather than an agreed verification design. Those limits are central: a statement that humans remain in control can conceal very different operating arrangements.
Test authority, time and intervention
Meaningful control needs at least three properties. First, the decision-maker must have authenticated authority and understand what decision is being delegated. Second, the system must preserve enough time and information for a human to evaluate alternatives; a millisecond escalation loop with a ceremonial confirmation is not control. Third, the person must have an intervention that predictably changes the outcome, including a safe stop or degraded mode.
Each property can become an exercise. Attempt to route an action through an unauthorised role and verify rejection. Compress the decision window and identify the point where human review becomes physically impossible. Remove or corrupt an input and check whether the system fails safely rather than manufacturing confidence. Test whether a stop command reaches every dependent component and whether operators can distinguish acknowledgement from execution.
The proposed hotline adds a fourth control: shared incident communication. Its value would depend on authentication, scope, availability under crisis conditions and rules for ambiguous attribution. A channel that exists on paper but is not exercised may add false confidence. Regular drills should cover technical errors, unauthorised action and uncertain origin without assuming that the other side accepts the explanation.
Keep principles and adoption separate
The strongest counterevidence is geopolitical. Shared words do not remove incentives to move quickly, conceal capabilities or interpret defensive automation as offensive. Verification can expose sensitive systems, while no inspection leaves compliance uncertain. The Brookings authors themselves identify speed, attribution and the security dilemma as continuing challenges.
That does not make operational definitions pointless. It makes bounded tests more valuable than broad assurance. Organisations outside defence can learn the same lesson without borrowing the military context literally: for any consequential agent, specify who may authorise, how much time and evidence they receive, what intervention changes state and how incidents are communicated.
The Skills Atlas can separate oversight literacy from system operation and crisis judgement. The immediate policy task is to turn “human control” into a small test protocol with pass/fail evidence. Record proposals, commitments and implemented mechanisms separately; do not report an expert recommendation as an adopted safeguard.
Specify the evidence for a pass
A test protocol needs observable evidence, not a declaration that a person was present. Preserve the authenticated identity and role of the decision-maker, the information displayed, the time available, the alternatives considered, the command issued and the resulting system state. Measure whether an operator detected uncertainty, whether the intervention arrived before the action boundary and whether dependent systems entered the intended safe mode.
Scenario diversity matters. Run benign false alarms as well as severe cases so operators are not trained to stop everything. Rotate ambiguous attribution, degraded communications, conflicting sensor reports and a loss of one command layer. Independent observers should score the exercise against predeclared criteria. A failed test should block the relevant operating mode until evidence shows the control works; otherwise “human control” becomes an audit label detached from system behaviour.