The Agreement (draft text)

From: An International Agreement to Prevent the Premature Creation of Artificial Superintelligence, Appendix A Authors: Aaron Scher, David Abecassis, Peter Barnett, Brian Abeyta (MIRI Technical Governance Team) Published: November 18, 2025 Report page: https://techgov.intelligence.org/research/an-international-agreement-to-prevent-the-premature-creation-of-artificial-superintelligence Full text: https://arxiv.org/abs/2511.10783 (arXiv:2511.10783, CC BY 4.0)

This file contains the full Appendix A of the report: the draft agreement text (Preamble and Articles I–XV) together with the per-article "Precedent" and "Notes" (commentary) annotation sections written by the authors.


Below, we provide an annotated example draft language for the sort of agreement that could be implemented by major governments around the world, if they recognized the dangers from artificial superintelligence (ASI) and sought to prevent anyone from building ASI. We present this as an illustrative example of some potentially valuable provisions to have in view, using mechanisms tailored to the situation at hand and grounded in historical precedent.

This draft text covers many different mechanisms that we think would be required to prevent AI developers from seriously endangering humanity. In practice, we would expect different aspects to likely be covered by different agreements.1 And of course, in reality, the parties involved should draft the agreement subject to negotiation and review by relevant experts.

For each article, we’ve provided a commentary section explaining why we made key decisions, and a section discussing some relevant precedent. It’s important to note that precedent is valuable because it demonstrates that the plan can be effectuated, not that it will be effective. The existence of prior agreements shows that similar mechanisms are politically and practically feasible, but does not guarantee they will achieve their intended outcomes in this domain. By contrast, our reasons for believing this particular agreement would be effective are discussed in various places, including the commentary sections, and are often AI-specific.

A real agreement would involve many details. We’ve included some level of detail, but also relegate much detail to “annexes” which would have to be finalized later. Many of the quantities and numerical thresholds we use in our draft constitute our best guess, but they should still be treated only as guesses. Many of those numbers would require further study and revision before being finalized. These sorts of details plausibly wouldn’t be included in the agreement itself, analogous to how, in the case of the Treaty on the Non-Proliferation of Nuclear Weapons (NPT), specific details of inspections and so-called “safeguards” programs were decided between each country and the IAEA, rather than being included in the NPT itself. However, for clarity, we have kept our best-guess numbers directly in the text, to help it feel more concrete.

Preamble

The States concluding this Agreement, hereinafter referred to as the Parties to the Agreement,

Alarmed by the prospect that the development of artificial superintelligence would lead to the deaths of all people and the end to all human endeavor,

Affirming the necessity of urgent, coordinated, and sustained international action to prevent the creation and deployment of artificial superintelligence under present conditions,

Convinced that the measures to prevent advancement of artificial intelligence capabilities will reduce the chance of human extinction,

Recognizing that the stability of this Agreement relies on the ability to verify the compliance of all Parties,

Recalling the precedent of prior arms control and nonproliferation agreements in addressing global security threats,

Undertaking to cooperate in facilitating the verification of artificial intelligence activities globally when they steer well clear of artificial superintelligence, and seeking to preserve access to the benefits of artificial intelligence systems even while avoiding dangers,

Have agreed as follows:

Precedent for this Preamble

The preamble of this agreement is modeled after that of The Treaty on the Non-Proliferation of Nuclear Weapons (NPT), which begins:

Considering the devastation that would be visited upon all mankind by a nuclear war and the consequent need to make every effort to avert the danger of such a war and to take measures to safeguard the security of peoples…

and soon adds:

Affirming the principle that the benefits of peaceful applications of nuclear technology, including any technological by-products which may be derived by nuclear-weapon States from the development of nuclear explosive devices, should be available for peaceful purposes to all Parties to the Treaty, whether nuclear-weapon or non-nuclear-weapon States…

In so doing, the preamble invites the world to join responsible parties in safeguarding humanity from the catastrophic threat of a powerful technology, and to share in the benefits that can be safely permitted. Our preamble tries to follow this example.

The NPT entered into force in 1970 and was extended indefinitely in 1995. Known for its near-universal membership (191 parties), its preamble emphasizes the global hazard of weapons proliferation while affirming that the benefits of peaceful nuclear applications should be available to all parties.

ARTICLE I — Primary Purpose

Each Party to this Agreement does not develop, deploy, or seek to develop or deploy artificial superintelligence ("ASI") by any means. Each Party prohibits and prevents all such development within their borders and jurisdictions, and, due to the uncertainty as to when further progress would produce ASI, does not engage in or permit activities that materially advance toward ASI as described in this Agreement. Each Party assists, or does not impede, reasonable measures by other Parties to dissuade and prevent such development by and within non-Party states and jurisdictions. Each Party implements and carries out all other obligations, measures, and verification arrangements set forth in this Agreement.

Where some classes of AI infrastructure and capabilities staying far from ASI may be deemed acceptable but only under conditions of international supervision, only Parties to the Agreement may carry out such activities, or own or operate AI chips and manufacturing capabilities that could potentially lead to the development of ASI if unsupervised. Non-Parties are denied such access for the safety of the Parties and of all life on Earth (Article V, Article VI, Article VII).

Parties commit to a dispute resolution process (Article XI) to minimize unnecessary Protective Actions (Article XII).

Precedent for Article I

Article I of the NPT, as in many treaties, states the high-level commitment parties are making — in this case, to not share their nuclear weapons or help others obtain them:

Each nuclear-weapon State Party to the Treaty undertakes not to transfer to any recipient whatsoever nuclear weapons or other nuclear explosive devices or control over such weapons or explosive devices directly, or indirectly; and not in any way to assist, encourage, or induce any non-nuclear-weapon State to manufacture or otherwise acquire nuclear weapons or other nuclear explosive devices, or control over such weapons or explosive devices.

The commitment summarized in Article I of our draft agreement is stronger than this because an ASI breakout by anyone, anywhere, cannot be allowed to happen even once.2 It would not be enough to not “assist, encourage, or induce” others to build it. We have therefore included a commitment to “assist, or not impede, reasonable measures” by parties to dissuade and prevent such development anywhere.

The NPT works to contain an existing threat (nuclear weapons), while our draft agreement is working to prevent a threat from existing at all (ASI). Precedent for preventing the development of dangerous new technology can be found in the Protocol on Blinding Laser Weapons, part of the Convention on Certain Conventional Weapons3. Its Article I reads:

It is prohibited to employ laser weapons specifically designed, as their sole combat function or as one of their combat functions, to cause permanent blindness to unenhanced vision, that is to the naked eye or to the eye with corrective eyesight devices. The High Contracting Parties shall not transfer such weapons to any State or non-State entity.

That language doesn’t try to keep anyone anywhere from ever testing or accidentally making such a system, however. Our agreement must be strong enough to prevent ASI from being made accidentally. Because it’s not clear where the point-of-no-return might be, our Article I includes a commitment to “not engage in or permit activities that materially advance toward ASI.”

ARTICLE II — Definitions

For the purposes of this Agreement:

  1. Artificial intelligence (AI) means a computational system that performs tasks requiring cognition, planning, learning, or taking actions in physical, social or cyber domains. This includes systems that perform tasks under varying and unpredictable conditions, or that can learn from experience and improve performance.

  2. Artificial superintelligence (ASI) is operationally defined as any AI with sufficiently superhuman cognitive performance that it could plan and successfully execute the destruction of humanity.

    • (a) For the purposes of this Agreement, AI development which is not explicitly authorized by the Coalition Technical Body (Article III) and is in violation of the limits described in Article IV shall be assumed to have the aim of creating artificial superintelligence.
  3. Dangerous AI activities are those activities which substantially increase the risk of an artificial superintelligence being created, and are not limited to the final step of developing an ASI but also include precursor steps as laid out in this Agreement. The full scope of dangerous AI activities is concretized by Articles IV through IX and may be elaborated and modified through the operation of the Agreement and the activities of the Coalition Technical Body.

  4. Floating-point operations (FLOP) is the computational measure used to quantify the scale of training and post-training, based on the number of mathematical operations done. FLOP shall be counted as either the equivalent operations to the half-precision floating-point (FP16) format or the total operations (in the format used), whichever is higher.

  5. Training run means any computational process that optimizes an AI’s parameters (specifications of the propagation of information through a neural network, e.g., weights and biases) using gradient-based or other search/learning methods, including pre-training, fine-tuning, reinforcement learning, large-scale hyperparameter searches that update parameters, and iterative self-play or curriculum training.

  6. Pre-training means the training run by which an AI’s parameters are initially optimized using large-scale datasets to learn generalizable patterns or representations prior to any task- or domain-specific adaptation. It includes supervised, unsupervised, self-supervised, and reinforcement-based optimization when performed before such adaptation.

  7. Post-training means a training run executed after a model’s pre-training. In addition, any training performed on an AI created before this Agreement entered into force is considered post-training.

  8. Strict Threshold is the amount of training computation (measured in FLOP) above which training runs are prohibited. It is set at 10^24 FLOP.

  9. Strict Post-training Threshold is the amount of training computation (measured in FLOP) above which post-training runs (e.g., of models trained before the agreement) are prohibited. It is set at 10^23 FLOP.

  10. Monitored Threshold is the amount of training computation (measured in FLOP) above which training runs are subject to monitoring by the international authority. It is set at 10^22 FLOP.

  11. Advanced computer chips are integrated circuits fabricated on processes at least as advanced as the 28 nanometer process node.

  12. AI chips mean specialized integrated circuits designed primarily for AI computations, including but not limited to training and inference operations for machine learning models [this would need to be defined more precisely in an Annex]. This includes GPUs, TPUs, NPUs, and other AI accelerators. This may also include hardware that was not originally designed for AI uses but can be effectively repurposed. AI chips are a subset of advanced computer chips.

  13. AI hardware means all computer hardware for training and running AIs. This includes AI chips, as well as networking equipment, power supplies, and cooling equipment.

  14. AI chip manufacturing equipment means equipment used to fabricate, test, assemble, or package AI chips, including but not limited to lithography, deposition, etch, metrology, test, and advanced-packaging equipment [a more complete list would need to be defined in an Annex].

  15. H100-equivalent means the unit of computing capacity (FLOP per second) equal to one NVIDIA H100 SXM accelerator, 989 TFLOP/s in FP16, or a Total Processing Performance (TPP) of 15,824 TFLOP-bit/s, where TPP is calculated as TPP = 2 × non-sparse MacTOPS × (bit length of the multiply input).

  16. Covered chip cluster (CCC) means any set of AI chips or networked cluster with aggregate effective computing capacity or accelerator memory greater than 16 H100-equivalents. A networked cluster refers to chips that either are physically co-located, have inter-node aggregate bandwidth — defined as the sum of bandwidth between distinct hosts/chassis — greater than 25 Gbit/s, or are networked to perform workloads together. The aggregate effective computing capacity of 16 H100 chips is 15,824 TFLOP/s, or TPP of 253,184 TFLOP-bit/s, and is based on the sum of per-chip TPP. The total accelerator memory of 16 H100 chips is 1,280 GB. Examples of CCCs would include: the GB200 NVL72 server, three eight-way H100 HGX servers residing in the same building, CloudMatrix 384, a pod with 32 TPUv6e chips, every supercomputer.

  17. National Technical Means (NTM) includes satellite, aerial, cyber, signals, imagery (including thermal), and other remote-sensing capabilities employed by Parties for verification consistent with this Agreement.

  18. Chip-use verification means methods that provide insight into what activities are being run on particular computer chips in order to differentiate acceptable and prohibited activities.

  19. Methods used to create frontier models refers to the broad set of methods used in AI development. It includes but is not limited to AI architectures, optimizers, tokenizer methods, data curation, data generation, parallelism strategies, training algorithms (e.g., RL algorithms) and other training methods. This includes post-training but does not include methods that do not change the parameters of a trained model, such as prompting. New methods may be created in the future.

  20. AI Technique Whitelist means the list of approved AI methods and techniques maintained by the Coalition Technical Body. Training runs above the Monitored Threshold may only use techniques on this list.

Notes on Article II

On Definitions of AI

The definition of AI used here (adapted from Senator Chuck Grassley’s AI Whistleblower Protection Act) is possibly too broad. Further refinement would help make it clear that the definition should not apply to obviously-safe computer systems such as spellcheck or image recognition systems.

If AI technology were never going to change from its modern form, in which development for a frontier Large Language Model requires highly specialized hardware and is easily distinguishable from other activities, it would be easier to craft a narrow tailored definition. But ASI is a moving target, and the definition of AI that is used must cover more than just LLMs. An agreement prohibiting solely machine learning might encourage researchers to develop new AI paradigms that don’t technically meet the definitions, so that they can race ahead toward superintelligence. If a novel paradigm did emerge, especially one which is not as AI-chip-intensive as deep learning, then the agreement would likely need to be updated, and enforcement might become substantially more difficult.

On Definitions of Computing Capacity

We use H100-equivalent as the primary metric for computing capacity. In Article V, this is used to set the size of the largest allowed unmonitored chip cluster (16 H100-equivalents). Article IV defines thresholds in terms of the total operations used to train an AI, and so, by setting limits on unmonitored operations per second, this effectively would make it infeasibly slow to conduct an illegally large training run on unmonitored hardware.

We use H100-equivalents because the most relevant metric in various chip designs is how quickly they perform operations, and H100s serve as a fine and precedented measuring stick. Other chip metrics are important in AI training (such as high bandwidth memory), but overall, these matter less than the number of operations per second.

Our proposed definition of a covered chip cluster (CCC) is an attempt to satisfy several constraints: The bound should be high enough to prevent regular people from breaking the rules (i.e., 25 Gbit/s bandwidth between chassis is faster than non-data center internet connections; it is very rare and expensive for an individual to own more than 16 H100-equivalents). The bound must also be set low enough to prevent dangerous AI activities and to make subversion difficult (i.e., make it difficult to do training distributed across multiple sub-CCC sets of chips). We discuss the tradeoffs more in the notes after Article V. The constraints on CCC accelerator memory are designed to prevent illicit distributed training, as discussed in this article.

AI chips are a subset of advanced computer chips, and there isn’t a bright line that distinguishes AI chips from non-AI chips. Instead of defining and relying on a distinction here, we use the overall computing capacity (in operations per second) of a cluster, as measured in H100-equivalents. If the chips could be configured for training or running AIs and are above the defined threshold, then the agreement requires that they be monitored.

Note that National Technical Means (NTM) may be deprecated as the official term by some governments. We use it in this agreement in the style of past arms control agreements for ease of comparison.

ARTICLE III — The Coalition

  1. Parties to this Agreement constitute the coalition. The coalition shall implement this Agreement and its provisions, including those for international verification of compliance with it, and shall provide a forum for consultation and cooperation among Parties.

  2. The organs of the coalition are the Executive Council and the Coalition Technical Body (CTB).

  3. Executive Council

    • (a) The Executive Council initially consists of the United States of America and the People’s Republic of China.

    • (b) The Executive Council: approves challenge inspections; appoints the Director-General; provides oversight of the CTB and exercises veto power over its recommendations; determines overall policy and adopts the budget.

    • (c) Decision-making processes are as follows:

      • i. All proactive Executive Council decisions require consensus among members. If consensus cannot be reached, the proposed changes are not adopted.
      • ii. Each member of the Executive Council has veto power over decisions by the CTB.
      • iii. The Executive Council may delegate specific authorities to the CTB, subject to the veto power described above.
    • (d) The Executive Council may hold deliberative sessions with selected additional Parties that are not on the Executive Council. These additional Parties are chosen by the Executive Council. Selected Parties may participate in debate and be provided with relevant sensitive information in order to do so.

  4. Coalition Technical Body (CTB) and Director-General

    • (a) The Director-General of the CTB is its head and chief administrative officer.

    • (b) The Director-General is appointed by the Executive Council for a four-year term, renewable once. The Executive Council can recall the Director-General.

    • (c) The CTB coordinates the activities of the Parties required by the Agreement. It includes technical divisions for Chip Tracking and Manufacturing Safeguards, Chip Use Verification Safeguards, Research Controls, Information Consolidation, Technical Reviews, Administration and Finance, and Legal and Compliance. The Director-General can create and disband technical divisions.

    • (d) The CTB, through the Director-General, proposes changes to technical definitions and safeguard protocols, as necessary to implement Article IV, Article V, Article VI, Article VII, Article VIII, Article IX, and Article X of this Agreement.

      • i. Time-sensitive changes to FLOP thresholds (Article IV), the size of covered compute clusters (Article V), and the boundaries of restricted research (Article VIII) may be implemented by the Director-General immediately in the case where inaction poses a security risk. Such changes remain in effect for thirty days. Past that, the changes require approval from the Executive Council to remain in effect, subject to the veto power of each Executive Council member.
  5. The coalition’s regular budget is funded by assessed contributions of members of the Executive Council, with the assessment scale determined by the Executive Council.

Precedent for Article III

The Intermediate-Range Nuclear Forces (INF) Treaty and Strategic Arms Reduction Treaties (START I, START II, and New START), place responsibility for implementation and verification on the individual parties; each commit to procedures that allow the other to obtain reasonable assurance of compliance.

The Executive Council established by paragraph 3 emulates the NPT’s Board of Governors.

Taiwan complicates our agreement concept, given its delicate geopolitical situation and its status as the producer of most of the world’s AI chips. Fortunately, precedent provides guidance: Though Taiwan is not a party to the NPT, it has stated on multiple occasions that it considers itself bound by the principles of the NPT. Taiwan allows the IAEA to conduct inspections and apply safeguards to its nuclear facilities through a trilateral agreement with the United States and the IAEA. A similar arrangement could be worked out with regard to this agreement.

The “challenge inspections” in paragraph 3, subparagraph (b) are modeled after the mechanism in Part X of the CWC; we will elaborate on this precedent with Article X.

Notes on Article III

This arrangement centralizes only those few functions which must be centralized (such as maintaining and clarifying limits on AI research, development, and deployment) within the Coalition Technical Body and provides oversight power to the Executive Council. One benefit to our draft structure is that it enables the technical body to carry out rapid decision-making, though these decisions must survive being vetoed by any Executive Council member.

In this agreement, the U.S. and PRC, and possibly other executive council members pursue parallel efforts at verifying and enforcing compliance (see also Article X). This aims to meet each party’s assurance needs while sacrificing the smallest amount of autonomy and not at all hampering pre-existing efforts at intelligence gathering.

It should be noted that the U.S. and PRC are the preeminent powers when it comes to AI technology. The viability of any agreement would require that both countries are party to any agreement whether it be bilateral or otherwise. Realistically, both countries will have an outsized say over restrictions, supply, and research given the current state of AI development. With this in mind, it’s also important to acknowledge that certain states, such as the permanent members of the UN Security Council, along with countries with substantial economic and military resources will only join this agreement if it is in line with their national security and economic interests. We are writing this agreement in such a way as to not take a preemptive stand on which countries would join the Executive Council. Ultimately it will be up to interested parties to the agreement to negotiate who is in the Executive Council based on relative negotiation advantages and positions going into such discussions.

Given the status of TSMC as the leading AI chip manufacturer, any AI agreement must consider how to address Taiwan. As discussed in the Precedent section, we would encourage Taiwan to adhere to our agreement much as it adheres to the NPT without having signed it, through formal arrangements and/or declarations stating that Taiwan considers itself to be bound by the principles of this agreement and is open to on-site routine and/or challenge inspections.

ARTICLE IV — AI Training

  1. Each Party agrees to ban and prohibit AI training above the following thresholds: Any training run exceeding the Strict Threshold or any post-training run exceeding the Strict Post-training Threshold. Each Party agrees to not conduct training runs above these thresholds, and to not permit any entity within its jurisdiction to conduct training runs above these thresholds.

    • (a) The Coalition Technical Body (CTB) may modify these thresholds, in accordance with the process described in Article III.
  2. Each Party shall report any training run above the Monitored Threshold to the CTB, prior to initiation. This applies for training runs conducted by the Party or any entity within its jurisdiction.

    • (a) This report must include, but is not limited to, all training code, all training data, and an estimate of the total FLOP to be used. The Party must provide CTB staff supervised access to all data, with access logging appropriate to the data’s sensitivity, and protections against duplication or unauthorized disclosure. Data and code may be reviewed on-site at the training facility or through secure mechanisms approved by the CTB. Failure to provide CTB staff sufficient access to data is grounds for denying the training run, at the CTB’s discretion. The CTB may request any additional documentation relating to the training run. The CTB will also pre-approve a set of small modifications that could be made to the training procedure during training. Any such changes will be reported to the CTB when and if they are made.
    • (b) Training runs above the Monitored Threshold require explicit approval from inspectors representing the U.S. and the PRC, physically present at the training facility. Inspectors must provide written approval before training may commence. Either may withhold approval or require modifications. Inspectors shall verify that the training code uses only AI techniques approved on the AI Technique Whitelist maintained by the CTB.
    • (c) Inspectors may not remove electronic storage devices or data from the training facility.
    • (d) The CTB may monitor such training runs, and the Party will provide checkpoints of the model to the CTB upon request, including the final trained model [initial details for such monitoring would need to be described in an Annex].
    • (e) In the event that monitoring indicates worrisome AI capabilities or behaviors, the CTB can issue an order to pause a training run or class of training runs until it deems it safe for the training run to proceed.
    • (f) The CTB will maintain robust security practices. The CTB will share information about declared training runs with the U.S. and PRC to support independent verification efforts.
    • (g) In the event that a Party discovers a training run above the designated thresholds, whether through the Party’s own verification efforts or otherwise, the Party must report this training run to the CTB and halt this training run (if it is ongoing). Such a training run may only resume with approval from the CTB.
  3. Each Party, and entities within its jurisdiction, may conduct training runs of less FLOP than the Monitored Threshold without oversight or approval from the CTB.

  4. The CTB may authorize specific carveouts for activities such as safety evaluations, self-driving vehicles, medical technology, and other activities deemed safe by the Director-General, subject to the Executive Council’s veto power under Article III. These carveouts may allow for training runs larger than the Strict Threshold with CTB oversight, or a presumption of approval from the CTB for training runs between the Monitored Threshold and Strict Threshold.

  5. The CTB creates and maintains an AI Technique Whitelist specifying allowed AI methods and techniques. The CTB may modify this Whitelist in accordance with Article III. Training runs above the Monitored Threshold may only employ techniques on this Whitelist.

Precedent for Article IV

While the numerical values for thresholds specified in our agreement can and should be revisited when moving beyond the early draft stage, quantitative caps are common in international agreements, preempting disputes that would otherwise hinge on differing interpretations of qualitative language.

The 1974 Threshold Test Ban Treaty established a cap of 150 kilotons on underground nuclear tests performed by the U.S. and USSR.4 The purpose and effect of this treaty was to at least somewhat hinder further development of larger and more destructive “city buster” warheads. A relevant parallel to AI development is that, as of mid-2025, more general and capable — and therefore more hazardous — models take correspondingly larger training runs to create; our agreement specifies caps intended to prevent such AIs from being intentionally developed, but also to reap the essential (if non-parallel) benefit of reducing the risk of an unforeseen capabilities threshold being accidentally and irretrievably crossed.

The training limit we have suggested as a starting point is low enough that some AI models trained today would exceed it; we see this as prudent in expectation of advances that make newer models more capable per unit of training (discussed with Article VIII). Arms reduction agreements provide precedent for thresholds set below the current maximum level. The 1922 Washington (Naval) Treaty set warship displacement limits that required the U.S. and other naval powers to scrap dozens of capital ships.5 In Article II of the 1991 START treaty,6 the U.S. and the Soviet Union (and later, the Russian Federation) agreed to limits in the sizes of their nuclear stockpiles and delivery systems that required them to phase out more than four thousand warheads each.

Precedent for quantitative thresholds that limit breakout potential will be discussed with Article V.

Notes on Article IV

In recent years, advances in AI have followed first and foremost from an increase in computational resources poured into AI training. Restricting these resources, and restricting algorithmic progress research (described in Article VIII), would dramatically reduce the risk that superintelligence could be created in the near term.

The restrictions in our draft are based on the number of computational operations used, as this is relatively easy to define and measure. The performance of existing state-of-the-art AI informs amounts of computing hardware that appear safe, at least when using AI algorithms from mid-2025.

We would prefer to limit training based on the capabilities of the trained system. But no one has the technical ability to confidently predict what a new AI will or won’t be able to do before it is trained. Computational resources are an available proxy.

The hard prohibition at the Strict Threshold (10^24 FLOP) for training is slightly below that used to train models near the state of the art as of August 2025 (such as DeepSeek-V3, trained with 3×10^24 FLOP). We suggest this threshold because it is below the level at which we expect AIs to be dangerous (given current algorithms), and because it provides some breathing room and a buffer against algorithmic progress.

The prohibition of post-training over 10^23 is meant to apply to the post-training of AIs created prior to the agreement entering into force. Many of these AIs will have been trained using more than 10^24 FLOP; as of mid-2025, there are between 50 and 100 such models. Given that the weights of many such AIs will have been openly released, it is not feasible to prevent people from using them, but it is feasible to prevent large modifications to them via post-training.

A 10^22 FLOP (Monitored Threshold) training run on 16 H100s would take around one week. This is computing-intensive enough that hobbyists would not accidentally break the threshold by training small and allowed models. AIs trained at the 10^22 scale (with current algorithms) have so far appeared to be innocuous, though that situation would need to be monitored, as it could change as a result of unprevented AI research progress.

Monitoring of medium-scale training would allow the CTB to stay (somewhat) up to date with any algorithmic progress that happens in spite of the bans, and Article XIII provides for evaluations of models trained in this band. This would help to apprise the CTB of trends in AI development and adjust the FLOP thresholds however merited.

CTB staff are permitted access to training data used in monitored training runs, subject to a variety of restrictions. The intent of the restrictions is to guarantee that logging and other oversight methods are used to prevent unauthorized disclosure of sensitive contents in the training data, including but not limited to personal identifying information, personal health information, classified data, trade secrets, and banking data subject to secrecy laws.

ARTICLE V — Chip Consolidation

  1. Each Party ensures that within their jurisdiction, all covered chip clusters (CCCs), as defined in Article II (i.e., a set of chips with capacity greater than 16 H100-equivalents) [note that 16 H100s collectively cost around $500,000 in 2025 and these are rarely owned by individuals], are located in facilities declared to the CTB, and that these AI chips are subject to monitoring by the Parties, coordinated by the CTB.

    • (a) Parties aim to avoid co-locating AI chips with non-ancillary non-AI computer hardware in these declared facilities.
    • (b) These facilities are accessible to physical inspection. This may include, for instance, that verification teams can reach any CCC from at least one airport with scheduled international service within 12 hours.
    • (c) Parties do not house AI chips in so many different locations that it is infeasible to monitor all locations. If requested by the CTB, Parties must further consolidate their AI chips into fewer monitored facilities.
  2. Unmonitored AI chips that are not part of a CCC (i.e., that have capacity less than 16 H100-equivalents) may remain outside of CTB-declared facilities, provided that such stockpiles are not aggregated or networked to meet the CCC definition, are not rotated among sites to defeat monitoring, and are not used for prohibited training. Parties will make reasonable efforts to monitor the sale and aggregation of AI chips to ensure that any newly created CCCs are detected and monitored and are not used for prohibited training.

  3. Within 120 days of the Agreement entering into force, each Party locates, inventories, and consolidates all CCCs into facilities declared to the CTB. Parties do not disaggregate, conceal, or otherwise reassign chips to evade this requirement or to cause a set of chips which would have been classified as a CCC to no longer be classified as a CCC.

  4. Parties to the Agreement monitor the domestic consolidation process, coordinated by the CTB, including through on-site inspections, document and inventory verification, accompaniment of domestic authorities during transfers and inspection, and information sharing with Parties under Article X. The CTB may require chain-of-custody records for transfers. Parties may conduct challenge inspections as described in Article X. Parties provide timely access to relevant facilities, transport hubs, and records to inspectors conducting monitoring activities. Whistleblower protections and incentives under Article X apply to the consolidation process, and the CTB maintains protected reporting channels.

  5. Within 120 days of the Agreement entering into force, Parties submit to the CTB a register of their CCCs. The register must include the location, type, quantity, serial or other unique identifiers where available, and associated interconnects of all AI chips in the CCCs. Each Party provides the CTB with an updated and accurate register no later than every 90 days.

  6. Parties provide the CTB with advance notice of any planned transfer of AI chips, whether domestic or international, no less than 14 days before the planned transfer. The CTB must approve any transfer before it proceeds. Inspectors are afforded the opportunity to observe the transfer. For international transfers, both the sending and receiving Parties coordinate with the CTB on routing, custody, and receipt. Emergency transfers undertaken for safety or security reasons notify the CTB and Executive Council as soon as practicable, and the CTB will verify the transfer occurred as reported.

  7. Broken, defective, surplus, or otherwise decommissioned AI chips continue to be treated as functional chips, until the CTB coordinates certification of their destruction. Parties do not destroy AI chips without oversight. Destruction or rendering permanently inoperable is conducted under oversight using CTB-approved methods and recorded in a destruction certificate submitted to the CTB [the details will need to be explained in an Annex]. Salvage or resale of components from such hardware is prohibited unless expressly authorized by the CTB.

Precedent for Article V

Declaring assets of concern is often a first step in restrictive treaties. Parties to the 1922 Washington Naval Treaty provided inventories of capital ships and their tonnage, and committed to notify each other when replacing these vessels. The 1991 START I treaty included a classified Agreement on Exchange of Coordinates and Site Diagrams (in Article VIII), outlining the sharing of data on the location of all declared strategic arms. Article V, paragraph 3 of our draft agreement requires parties to locate, inventory, and consolidate covered chip clusters within 120 days.

Consolidating assets to facilitate verification of compliance is often another step in restrictive treaties. Article III of START I forbade ICBMs from being co-located with space-launch facilities, easing monitoring. Paragraph 1, subparagraph (a) commits parties to “avoid co-locating AI chips with non-ancillary non-AI computer hardware in these declared facilities” for the same reason.

Another reason to pursue consolidation is to limit breakout potential (breakout is when a party attempts to create ASI before anyone else can stop them). Consolidated assets are easier to surveil and disable if necessary. The anticipation of a credible disabling action improves the effectiveness of deterrence-by-denial.

Monitoring and inspections are common components of prior treaties in limited-trust contexts; we have consequently drafted provisions for this where appropriate, in paragraphs 1, 4, 6, and 7 of this article. Some specific precedent for this:

  • Verification of START I included hundreds of on-site inspections in the first few years.
  • The CWC requires the declaration and inspection of all Chemical Weapons Production Facilities — there have been 97 declared — and the majority of these have been verifiably destroyed. (In requiring the declaration of existing facilities, these agreements also prohibit certain activities from occurring outside declared facilities, analogous to this article’s prohibition on unmonitored CCCs.)
  • Over 700 declared nuclear facilities around the world are monitored by the IAEA as part of the NPT.

Similar to paragraph 3 of this article, numerous arms control agreements require that parties not interfere with each other’s NTM in the context of verification. Examples include SALT I,7 ABM,8 INF,9 and START I.

Precedent for parties restricting their domestic private sector industries to meet commitments (as would need to be the case with AI) can be seen in U.S. legislation following its ratification of the CWC: The Chemical Weapons Convention Implementation Act of 1998 and Department of Commerce regulations ensured U.S. entities were in compliance. Similarly, the U.S. Congress amended the Clean Air Act following ratification of the Montreal Protocol to ban ozone-depleting substances.

Approaches to implementing chip centralization in the U.S. might run through the Fifth Amendment’s Takings Clause, in which the government can use its power of eminent domain to seize private property for public purposes, so long as it pays appropriate compensation.

Notes on Article V

Article V aims to centralize, into monitored facilities, all AI chip clusters (i.e., sets of interconnected chips above a small size) and the vast majority of AI chips. Monitoring and prevention of proliferation are covered in Article VI.

Our draft specifies international verification of this centralization process so that all parties can confirm that all other parties have also centralized their chips. Verification of this type is likely to be straightforward for large AI data centers, as intelligence agencies are likely to already know where these are. For smaller data centers, the CTB can coordinate oversight of domestic centralization efforts.

Chip centralization is an important first step to restricting the development of artificial superintelligence. Centralizing chips in declared facilities enables further monitoring for how these chips are being used, or verification that they are powered off (if they are not safe to use). Centralization would also make it easier for parties to disable these chips, as might become necessary under Article XII, if a Party persists in violating the agreement.

We avoid recommending, in the text of the agreement, that CCCs be located away from population centers, despite their capacity for danger. We avoid this restriction both because (in the case of agreement violations) data centers can likely be shut down without much collateral damage, and because modern data centers are already regularly located near cities. That said, alternative agreements might prefer to treat AI data centers as military facilities, given their potential to pose grave security threats.

Verifying Centralization

Most parties would not and should not blindly trust other parties to follow the rules, and would need some way to verify compliance. The centralization of AI chips into declared facilities makes it possible for inspections and monitoring to confirm the presence and activity of the chips.

Centralization might not be strictly necessary if there are other ways to monitor AI chips. Unfortunately, we think this is currently the only feasible option short of physically destroying all existing stockpiles of AI chips, given the limited security mechanisms in current chips today.

In the future, hardware-enabled governance mechanisms could be developed to enable remote governance of AI chips, so that chips don’t need to be centralized to declared locations. Aarne et al. (2024) provide estimates for the implementation time of some of these on-chip governance mechanisms. Their estimates cover the timeline to develop mechanisms that are robust against different adversaries. For concision, we will use their estimates for security in a covertly adversarial context where competent state actors may try to break the governance mechanisms but would face major consequences if caught. They estimate a development time of two to five years for ideal solutions, with less secure but potentially workable options available in just months.

Even though that report is over a year old, we are not aware of significant progress toward these mechanisms, and we think two to five additional years is the most relevant estimate from Aarne et al. Which is to say that, possibly, after a few years of research and development into chip security measures, it would be possible to confidently monitor chips without centralizing them, after some further lag time for new securely-monitorable chips to be produced, and/or for old chips to be retrofitted. Aarne et al. estimate that the first of these options might take four years, but we are optimistic that retrofitting could be done in one to two years if chips are already being tracked.

While centralization as discussed in Article V entails the physical concentration of covered chip clusters, it does not require that governments take ownership of chips. For large data centers, the agreement permits the data center and its chips to remain where they are, under private ownership, so long as they receive monitoring and oversight from the relevant parties. This monitoring would ensure that data centers are engaged only in non-AI activities or permitted AI activities like running old models. For smaller chip aggregations, it may be necessary to physically move them into a larger data center, with their owner continuing to access the chips remotely; we do not consider this an overly onerous restriction given that it is already common in cloud computing arrangements.

Feasibility

It looks feasible to verifiably consolidate the majority of AI chips. The very largest AI data centers, such as those with more than 100,000 H100-equivalents, are hard to hide. They are detectable from their physical footprint and power draw, and many of them are publicly reported on. In fact, it’s probably possible for intelligence services to track and locate data centers as small as around 10,000 H100-equivalents. Locating smaller data centers would involve domestic authorities using various powers in cooperation with CTB inspectors.

States have a range of tools available for tracking down chips owned domestically. They can legally require reporting of all chip clusters larger than 16 H100s; they can use sales records and other financial information from chip distributors; they can interview technicians with expertise in data center construction; etc. If they suspect smuggling, obfuscation, or concealment of chips, they can employ law enforcement to investigate further. This process of domestic centralization would be overseen by CTB inspectors to ensure thorough compliance.

Locating large data centers could happen quickly, in days or weeks. Actually centralizing chips could take longer, as it might be necessary to build further data center capacity in the facilities that would become CCCs.

One significant challenge is providing justified confidence that one Party is not doing a secret AI project with non-declared AI chips. Chip centralization provides some assurance, but it may not be sufficient if some country could purposefully undermine its own domestic centralization efforts. For further assurances against illegal AI projects, see the intelligence gathering and challenge inspections discussed in Article X.

For a longer discussion of chip consolidation, see Appendix D.

On the Definition of CCCs

Our definition of CCC draws a line at 16 H100-equivalents. This threshold aims to meet a few criteria:

  • Monitoring chip clusters larger than 16 H100s works well with the training FLOP thresholds in Article IV. Training with 16 H100s (FP8 precision, 50 percent utilization — realistic but optimistic parameters) would take 7.3 days to get to 10^22 FLOP (the Monitored Threshold), and 2 years to get to 10^24 FLOP (the Strict Threshold). Therefore, it would be feasible for people to use undeclared chips to reach the bottom threshold, but it would be somewhat impractical for them to get to the prohibited training threshold.
  • This threshold is plausibly sufficient for preventing the advancement of AI capabilities, when combined with bans on AI research in Article VIII. Article IV lays out training restrictions where large-scale training is prohibited and medium-scale training is allowed but subject to oversight. It is probably acceptable — that is, it probably poses minimal risk — to allow small-scale training, such as the amount that can be done on 16 H100s in a realistic time frame.
  • This threshold has limited impact on hobbyists and consumers. Very few individuals own more than 16 H100s. In mid-2025, a set of 16 H100 chips cost around $500,000. This isn’t a threshold one would accidentally cross by having a few old gaming consoles laying around.
  • Consolidating AI chips gets harder as the allowable quantity shrinks. Finding data centers with 100,000 chips is easy; finding those with 10,000 is likely also relatively easy; with 1,000 it’s unclear; and below 100, it may start to become quite difficult. The 16 H100 threshold is likely to be challenging, and is picked partially due to the increasing infeasibility of still lower thresholds.
  • Despite potential enforcement challenges, it is possible that this definition would need to be revised and the threshold brought lower (e.g., 8 H100-equivalents). In our agreement, the CTB would be tasked with assessing this definition and changing it as needed.

Other Considerations

This article calls for parties to avoid co-locating AI chips with non-ancillary non-AI chips. This is suggested because co-location might make verification of chip use (Article VII) more difficult. However, this is not strictly necessary, and it may not be desired. AI chips are currently often colocated with non-AI chips, and the inconvenience of changing this could outweigh the inconvenience of monitoring and verifying the AI chips in a data center that mixes AI chips with non-AI chips.

There is some risk that private citizens could construct an unmonitored CCC from “loose” H100-equivalent chips. To combat this, the agreement holds that parties shall make “reasonable effort” to monitor chip sales (in excess of 1 H100-equivalent) and detect the formation of new CCCs. More stringent measures could be taken, such as requiring all such chips and sales to be formally registered and tracked. Our draft does not go to that length, both because we do not expect all that many “loose” H100-equivalent chips to be unaccounted-for after all chips in CCCs are cataloged, and because other mechanisms (such as the whistleblower protections in Article X) help with the detection of newly-formed CCCs.

Rather than immediately requiring small clusters (e.g., 100 H100s) to be centralized, the agreement could instead implement a staged approach. For example: In the first 10 days all data centers with more than 100,000 H100-equivalent chips must be centralized and declared, then in the next 30 days all data centers with more than 10,000 H100-equivalent chips must be centralized and declared, etc. A tiered approach might better track international verification capacity as intelligence services ramp up their detection efforts.

One downside of a staged approach is that it might provide more opportunities for states to hide chips and establish secret data centers. This approach nevertheless parallels how some previous international agreements have worked within the constraints of their verification and enforcement options. For instance, the 1963 Partial Test Ban Treaty did not ban underground testing of nuclear weapons, due to the difficulty in detecting such tests.

ARTICLE VI — AI Chip Production Monitoring

  1. The CTB will coordinate monitoring of AI chip production facilities and key inputs to chip production. This monitoring will ensure that all newly produced AI chips are immediately tracked and monitored until they are installed in declared CCCs and that unmonitored supply chains are not established.

    • (a) The CTB will coordinate monitoring of AI chip production facilities determined to be producing or potentially producing AI chips and relevant hardware [the precise definitions of AI chip production facilities, AI chips, and relevant hardware would need to be further described in an Annex; the monitoring methods would also need to be described in an Annex].
    • (b) Monitoring of newly produced AI chips will include monitoring of production, sale, transfer, and installation. Monitoring of chip production will start with fabrication. The full set of activities includes fabrication of high-bandwidth memory (HBM), fabrication of logic chips, testing, packaging, and assembly [this set of activities would need to be specified in an Annex].
  2. For facilities where tracking and monitoring is not feasible or implemented, production of AI chips will be halted. Production of AI chips may continue when the CTB declares that acceptable tracking and monitoring measures have been implemented.

  3. If a monitored chip production facility is decommissioned or repurposed, the CTB will coordinate oversight of that process, and, if done satisfactorily, this ends the monitoring requirement.

  4. No Party sells or transfers AI chips or AI chip manufacturing equipment except as authorized and tracked by the CTB.

    • (a) Sale or transfer of AI chips within or between Parties to the Agreement has a presumption of approval and is tracked by the CTB.
    • (b) Sale or transfer of AI chip manufacturing equipment within or between Parties to the Agreement does not have a presumption of approval. Approval for such transfer requires consensus of the Executive Council, based on an assessment of the risk of diversion or withdrawal from the Agreement of the receiving Party.
    • (c) Sale or transfer of AI chips and AI chip manufacturing equipment to non-Party States or entities outside a Party State has a presumption of denial.
  5. No Party sells or transfers non-AI advanced computer chips or non-AI advanced computer chip manufacturing equipment to non-Party States or entities outside a Party State except as authorized and tracked by the CTB.

  6. Sale or transfer of non-AI advanced computer chips or non-AI advanced computer chip manufacturing equipment within or between Parties to the Agreement is not restricted under this Article.

  7. To prevent accumulation of excess chip production capacity that could enable rapid breakout from the Agreement, the Executive Council may impose limits on total annual production of AI chips. Such limits aim to allow replacement of aging chips and modest expansion for approved applications while preventing stockpiling that would reduce the time required for a Party to develop ASI after withdrawal.

Precedent for Article VI

Treaty provisions for monitoring production facilities are not new. Article XI of the 1987 INF allowed for thirteen years of inspections of designated facilities where intermediate-range nuclear delivery systems had previously been produced; Section VII of the accompanying inspection protocol permitted continuous perimeter and portal monitoring that could include weighing (and in some cases x-raying) any vehicle leaving the facility large enough to carry a relevant missile.

Monitoring AI chip production is more complicated, due to the difficulty of discerning a chip’s function and capabilities from outward characteristics; this is why our Article VI stipulates that “relevant hardware would need to be further described in an Annex,” along with monitoring methods. But the experience of IAEA safeguards under the NPT shows that verification of a wide variety of production components and precursors across a supply chain is possible. One way the IAEA does this is by providing guidelines for the design of facilities to make them inspection friendly and reduce compliance costs.

Transfer embargoes on end-products, precursors, and production equipment (like the one suggested here on sale or transfer of AI chips and advanced computer chip manufacturing equipment to non-Party states or entities) all have substantial precedent:

  • In Article I of the NPT, each nuclear-weapon state commits “not to transfer to any recipient whatsoever nuclear weapons or other nuclear explosive devices” In its Article III, paragraph 2, they also agree not to provide a “source or special fissionable material” or equipment “especially designed or prepared for the processing, use or production of special fissionable material.”
  • Article I of the CWC likewise commits parties to never “transfer, directly or indirectly, chemical weapons to anyone”; its Article VII requires them to subject listed precursors to specified “prohibitions on production, acquisition, retention, transfer, and use”
  • The Cold-War-era Coordinating Committee for Multilateral Export Controls (CoCom) established a coordinated set of export controls from Western Bloc countries to the Communist Bloc, covering nuclear-related materials, munitions, and dual-use industrial items such as semiconductors.
  • The Nuclear Suppliers Group is a multilateral export control regime that restricts the supply of nuclear and nuclear-related technology that could be diverted to nuclear weapons programs.
  • Especially relevant is the series of U.S. export controls that have focused on AI chips and advanced chip manufacturing equipment, covering dozens of countries in the last couple years.
Notes on Article VI

The AI chip supply chain is narrow and specialized, making it feasible to monitor production. The vast majority of AI chips are designed by NVIDIA. The most advanced logic chips (the main processor) used in AI chips are almost all fabricated by TSMC — accounting for around 90 percent of market share. Most AI chips are fabricated on versions of TSMC’s five-nanometer process node, a node likely only supported by two or three manufacturing plants. EUV lithography machines, a critical component in advanced logic chip fabrication, are made exclusively by ASML. High-bandwidth memory (HBM), another key component to AI chips, is dominated by two or three companies. This narrow and technical supply chain would be relatively easy to monitor and hard to clandestinely replicate. We don’t want to overstate things too much—for example, China has an emerging domestic supply chain that produces some notable AI chips—but even with various caveats like this, monitoring existing chip production seems quite feasible.

Monitoring AI chip production would have relatively small spillover effects. While some of the same processes also produce other chips (e.g., smartphone chips), the chips themselves are easily differentiated. Chip design would change over time, but as a snapshot, current AI chips would be identifiable via their large high-bandwidth memory (HBM) capacity and specialized matrix-multiply components, among other factors.

When it comes to monitoring the AI chip supply chain, based on existing bottlenecks, a good start might be to monitor HBM production, logic die fabrication, and subsequent steps (e.g., packaging, testing, server assembly), along with key inputs such as EUV lithography machines.

Our Article states that sales of AI chips within Party states will have a presumption of approval, but does not indicate this presumption for AI chip manufacturing equipment. Chip sales are likely to have a relatively short-term effect on AI development capacity, as the lifecycle of AI chips is typically only a few years. By contrast, chip manufacturing capacity could lead to significant chip production for many years to come, and it would be especially concerning if a country became a Party, built up an AI chip supply chain, and then withdrew from the agreement. Therefore, we suggest more conservative restrictions on chip manufacturing equipment than on chips themselves.

Paragraphs 4 and 5 of this article permit the sale of AI chips and chip manufacturing equipment to Parties but not to non-Party states or other entities. That is, parties accept risks from chip manufacturing and concentration, but only in cases where the chips are subject to monitoring. The ability to manufacture and possess chips without a protective response from other states thus emerges as a positive incentive to join the agreement.

On its own, this does not prevent non-parties from accessing AI chips in Parties remotely (i.e., cloud computing, or Infrastructure-as-a-Service), but such chips would be under CTB monitoring to ensure they are not being used in violation of Article IV.

Restrictions on non-parties could go further, if need be. For example, non-parties could be banned from remote access to AI chips (i.e., from renting AI chips in Parties via the cloud) or from accessing AI models via APIs.

If monitoring chip production and preventing smuggling were infeasible, another approach would be to ban all production of new AI chips. This approach would run less of a risk of chips being diverted, but it has the cost of losing the value that these chips could have produced in non-research, non-development AI applications. It would still rely on some monitoring of chip production facilities — e.g., to ensure they are only producing non-AI chips or that they are decommissioned. Our agreement design invites chip production to continue due to the large benefits their use might bring, with the dangers mitigated by monitoring (Article VII).

ARTICLE VII — Chip Use Verification

  1. Parties accept continuous on-site verification of total chip usage at declared CCCs. The methods used for verification will be determined and updated by the CTB, in accordance with the process described in Article III. These methods may include, but are not limited to:

    • (a) In-person inspectors
    • (b) Tamper-proof cameras
    • (c) Measurements of power, thermal, and networking characteristics (i.e., off-chip monitoring mechanisms)
    • (d) On-chip hardware-enabled mechanisms, including retrofitted mechanisms and remote deactivation capabilities that allow the Executive Council to disable chips if compliance cannot be verified
    • (e) Declaration of the workloads and operations of chips by the CCC operator
    • (f) Rerunning of declared workloads, coordinated by the CTB, to confirm fidelity of declarations
  2. The aim of this verification is to ensure chips are not being used for prohibited activities, such as large-scale AI training described in Article IV.

  3. In cases where the CTB assesses that current verification methods cannot provide sufficient assurance that the AI hardware is not being used for prohibited activities, AI hardware must be powered off, and its non-operation continually verified by in-person inspectors or other CTB-approved verification mechanisms.

  4. The CTB may impose various restrictions on how chips can operate in order to ensure proper verification. These restrictions may include but are not limited to:

    • (a) Restrictions on the bandwidth and latency between different chips, or between chips and their data center network, in order to distinguish permitted inference from prohibited training.
    • (b) Restrictions on the number or rate of FLOP/s or memory bandwidth at which chips can operate, in order to distinguish permitted inference from prohibited training or other prohibited workloads.
    • (c) Restrictions on the numerical precision of chip operations, in order to differentiate AI from non-AI workloads.
  5. The CTB will coordinate differentiated verification approaches for different CCCs based on their likelihood of being used for AI activities and their sensitivity as relevant to national security.

    • (a) More sensitive facilities might have more technical/automated verification methods, less extensive physical access for foreign inspectors, and enhanced security protocols for inspector access.
  6. The CTB will lead research and engineering to develop better technologies for chip use monitoring and verification. Parties will support these efforts [more details would be provided in an Annex].

Precedent for Article VII

In our discussion of precedent for Article VI, we described the continuous monitoring of former intermediate-range missile production sites under the INF treaty, which, while allowing for weighing and non-destructive scanning of vehicles leaving the facilities, did not allow inspectors inside the trucks or the sites themselves. Analogous perimeter monitoring of data centers can provide some clues about operations from power draw, thermal emissions, and network bandwidth. But reasonable assurance that restricted AI operations are not occurring would likely require some combination of the elements we listed under paragraph 1, which includes tamper-proof cameras, on-chip hardware-enabled mechanisms, and in-person inspectors.

Such practices are already routine for the International Atomic Energy Agency, which is increasingly using around-the-clock surveillance technologies to supplement inspections:

Over a million pieces of encrypted safeguards data are collected by over 1400 surveillance cameras, and 400 radiation and other sensors around the world. More than 23 000 seals installed at nuclear facilities ensure containment of material and equipment.

One of the methods used under START I to verify compliance with missile performance characteristics was the sharing of almost all telemetry data transmitted from in-flight sensors during tests, as specified in the telemetry protocol, which also required parties to provide any playback equipment and data formatting information necessary to interpret it. Depending on the mix of verification methods adopted, some Parties may use analogous methods, building on the light-touch monitoring that is common practice for cloud computing providers to collect about customer workloads.

Continuous government monitoring of private commercial facilities (as most data centers are) also has plenty of precedent. The U.S. Nuclear Regulatory Commission, tasked with overseeing domestic nuclear reactor safety, places two resident inspectors in each U.S. commercial power plant, and U.S. meat producers cannot conduct slaughter operations if inspection personnel from the FSIS10 are not on site to oversee them.

Notes on Article VII

Parties would want to ensure that existing AI chips are not being used to do dangerous AI training. There are legitimate reasons to use these chips to run existing AI services like (extant versions of) ChatGPT. The agreement thus requires the ability to verify that AI chips are only being used for permitted activities.

This article creates a positive incentive to join the agreement: A country may continue using AI chips as long as supervision can verify that their use does not put the world at risk. Given the goal of preventing large-scale AI training, there are two main approaches: Ensure nobody has the necessary hardware (i.e., that AI chips do not exist), or ensure that the hardware is not used in the development of superintelligence (i.e., via monitoring). Monitoring is what permits the continued safe use of AI chips. This is conceptually analogous to IAEA Safeguards: In order for a non-nuclear weapon country to be permitted nuclear materials and facilities, it is necessary for the IAEA to inspect and ensure the use is only for peaceful purposes.

Feasibility

Various technical methods could be used to make verification easier. For example, using the algorithms of 2025, AI training requires much higher bandwidth compared to AI inference. Thus, if the chips are connected using low-bandwidth networking cables, they are effectively limited such that they can engage in inference but not training. There are various nuances to these and other mechanisms; we refer curious readers to previous work on the topic.

This article tasks the CTB with developing and implementing better verification mechanisms, defined broadly. We think this flexibility is necessary due to the pace of change in AI and the possibility that unanticipated developments could disrupt verification methods. The state of AI verification research is also nascent; more technological development in verification technology is a key opportunity.

It is much easier to verify whether a new AI is being created than it is to verify that an existing AI is not performing dangerous inference tasks (such as research that advances the creation of superintelligence). As of August 2025, existing AIs don’t obviously seem capable enough for their inference activities to substantially advance the creation of superintelligence, and so the monitoring challenge is easier.

It is unclear how difficult it would be to monitor AI inference activities. Inference monitoring is already applied by many AI companies today, for instance to detect if users are trying to use AIs to make biological weapons, but it is unclear whether that monitoring is comprehensive, and it is unclear whether it would get less reliable if AIs were allowed to become more capable. The longer that AI capabilities are allowed to advance before an agreement resembling our draft comes into effect, the more difficult monitoring would become. Verification that chips are only being used for permitted purposes would become more difficult and more expensive, or might even become impossible.

Other Considerations

In theory, verification could be facilitated by technological means that allow for remote monitoring. However, current technology likely contains security vulnerabilities that would allow chip owners to bypass monitoring measures. Thus, verification would likely require either continuous on-site monitoring or that chips be shut off until the technological means mature. Once monitoring technology is mature, strong hardware-enabled governance mechanisms could allow chips to be monitored remotely with confidence.11

Paragraph 5 of this article allows for different verification methods for different CCCs. One reason for this discrimination is practical: Different CCCs would require different verification approaches in order to establish justified confidence that they are not being used for dangerous AI development. For example, large data centers that were previously being used for frontier AI training would have the greatest ability to contribute to prohibited training and so might require greater monitoring.

Second, discrimination in verification approaches would make the agreement more palatable by requiring less invasive monitoring for sensitive CCCs. For example, intelligence agencies or militaries may not want any monitoring of their data centers (which may have more computing power than 16 H100-equivalents despite being used for purposes that have nothing to do with AI), and this provision helps strike a balance. It would still be necessary to verify that these data centers are not being used for dangerous AI activities, and the Executive Council members would work through the CTB with these groups to ensure it can get the information it needs while also meeting the privacy and security needs of CCC owners. On the other hand, allowing different verification protocols might hurt the viability of the agreement if it is viewed as unfair.

Our draft agreement allows chip use and production to continue so that the world may benefit from such chips. One alternative approach is to shut down new chip production and/or destroy existing chips. Absent algorithmic advancements, the destruction of chips would increase the “breakout time” — the time it takes between when a group starts trying to create a superintelligence and the point at which they succeed. This is because (in lieu of algorithmic advancements), a rogue actor would need to develop the capability to produce chips, which is a lengthy and conspicuous process. However, because we think it’s feasible to track chips and verify their usage, we do not think that the benefit of longer breakout times is clearly worth the cost of shutting off all AI chips.

ARTICLE VIII — Restricted Research: AI Algorithms and Hardware

  1. For the purpose of preventing the development of artificial superintelligence, this Agreement restricts only research that would materially advance toward ASI or undermine verification of compliance with this Agreement. This includes research in the field of machine learning and research in other artificial intelligence paradigms. Research focused on specific applications (such as medical diagnosis, scientific discovery, or industrial automation) that does not advance general cognitive capabilities toward ASI levels is not restricted. Restricted research includes:

    • (a) Improvements to methods for training general-purpose AI systems that would significantly increase model capabilities toward superintelligent performance or dramatically reduce the computational resources required to develop such systems
    • (b) Distributed or decentralized training methods that would enable ASI development outside of monitored facilities, or training methods specifically optimized to evade the computational thresholds in Article IV
    • (c) Advancements in the fabrication of AI-relevant chips or chip components
    • (d) Design of more performant or more efficient AI chips
  2. Application-specific AI research and development that does not advance general cognitive capabilities is permitted and encouraged. This includes research in domains such as medical diagnostics, drug discovery, materials science, climate modeling, robotics for specific tasks, and other specialized applications.

  3. The CTB’s Research Controls division classifies all restricted research activities as either controlled or prohibited.

    • (a) Each Party monitors any controlled research activities within its jurisdiction, and takes measures to ensure that all controlled research is monitored and made available to the Research Controls division for review and monitoring purposes.
    • (b) Each Party does not conduct any prohibited research, and prohibits and prevents prohibited research by any entity within its jurisdiction.
  4. Parties to the Agreement must not assist, encourage, or share prohibited research, including by funding, procuring, hosting, supervising, teaching, publishing, providing controlled tools or chips, or facilitating collaboration.

  5. Each Party provides a representative to the CTB’s Research Controls division (established in Article III). This division has these responsibilities:

    • (a) Interpret and clarify the categories of restricted research, and respond to questions as to the boundaries of restricted research, in response to new information, and in response to requests from researchers or organizations, or Party members.
    • (b) Interpret and clarify the boundary between controlled research and prohibited research, and respond to questions as to this boundary, in response to new information, and in response to requests from researchers or organizations or Party members.
    • (c) Modify the definition of restricted research and its categories, in response to changing conditions, or in response to requests from researchers or organizations or Party members.
    • (d) Modify the boundary between controlled research and prohibited research in response to changing conditions, or in response to requests from researchers or organizations or Party members.
    • (e) The CTB may modify the categories, boundaries, and definitions of restricted research in accordance with the process described in Article III.
Precedent for Article VIII

Pre-emptive restrictions on the dissemination of information related to dangerous technology find precedent in the Atomic Energy Act of 1946, still in force, which established information on certain topics as Restricted Data by default (the “born secret” doctrine); exclusions were at the discretion of the new Atomic Energy Commission created by this legislation:12

The term “restricted data” as used in this section means all data concerning the manufacture or utilization of atomic weapons, the production of fissionable material, or the use of fissionable material in the production of power, but shall not include any data which the Commission from time to time determines may be published without adversely affecting the common defense and security.

Unlike other types of government classification, Restricted Data can be created (deliberately or accidentally) by the private sector, a matter of unresolved constitutionality13 that highlights the need for a regulatory arm authorized and capable of making everyday decisions about the exact boundaries of Restricted Data. The National Nuclear Security Administration (NNSA) does this for nuclear secrets in the U.S. Under our Article VIII, paragraph 5, the Research Controls division would take on this role for restricted AI research. It would also fill other NNSA-analogous functions, outlined in our Article IX, by (1) maintaining relationships with researchers and organizations working on projects that approach the classification threshold, and (2) establishing secure infrastructure for reporting and containment of inadvertent discoveries.

There is also precedent for containing and controlling research in dangerous fields. In the final months of World War II, the U.K. and U.S. collaborated on the Alsos Mission to capture German nuclear scientists, gather information about German progress toward an atomic bomb, and prevent the USSR from obtaining these resources for its own nuclear program. Project Overcast (also called Operation Paperclip) was a secret U.S. program to take German rocket engineers into U.S. employment after the war.

Containment of restricted AI research within Party states might run through existing regulatory frameworks. In the U.S., these include:

  • The “deemed exports” concept in export control law, which obliges a U.S. entity to obtain an export license from the Bureau of Industry and Security14 before sharing controlled technologies with foreign persons by deeming such sharing as an export.
  • The International Traffic in Arms Regulations (ITAR), a set of U.S. State Department regulations that control the export of military and some dual-use technologies. ITAR was used to prevent the broader development and use of cryptographic techniques by the private sector until 1996, as these were classified as a “defense article” on the United States Munitions List.
  • The Invention Secrecy Act of 1951, which gives U.S. government agencies the power to impose “secrecy orders” on new patent applications with national security implications. Inventors can not only be denied patents, but legally prohibited from disclosing, publishing, or even using their inventions.15

Project Overcast also provides precedent for controlling researchers by simply paying them well to act in the interest of the state. Additional precedent for such incentives is discussed with Article IX.

The 1975 Asilomar Conference on Recombinant DNA is evidence that scientists themselves may voluntarily agree to research prohibitions, especially when faced with novel threats they are not sure they can contain. This conference resulted in voluntary guidelines around recombinant DNA research. These guidelines included prohibitions on certain especially dangerous experiments, such as cloning recombinant DNA from highly pathogenic organisms and DNA containing toxin genes.

Notes on Article VIII

Prohibiting several broad categories of research, when relevant know-how is already distributed in the private sector, presents a challenge. In our draft, research is restricted if it advances AI capabilities or performance, or if it endangers the verification approach laid out in previous articles.

Some research must be prohibited to prevent AI capabilities from advancing, even when holding the amount of training FLOP constant. This prohibition would need to cover all research that might make AIs more efficient to train or that might increase the capabilities of AIs, often referred to as “algorithmic progress.” In current paradigms, this includes advances in the algorithms used in pre-training, post-training, and inference. The AI development paradigm might shift and other AI development paradigms might catch up to machine learning. Therefore, the agreement should not constrain itself to only research in machine learning, even if this is the most urgent priority today. The agreement keeps the door open to potentially restrict research in other AI paradigms (e.g., connectomics, brain-inspired AI, fast genetic algorithms, GOFAI), if research in those paradigms seems likely to lead to ASI.

Previous algorithmic innovations, such as the development of the transformer architecture, demonstrate the potential for rapid advances in AI capabilities. Continued innovation could dramatically lower the amount of computational resources required for a given level of AI capability. As a feasibility argument, observe that modern AIs are much less data-efficient than human beings, which suggests that much more data-efficient algorithms can be found.

It is much harder to prevent the training of dangerous AIs when they can be trained with a small number of AI chips, or with many chips geographically dispersed in small clusters.

Separately, a prohibition must preclude research into new ways to manufacture untracked AI chips. Monitoring and verification of AI chips is feasible in large part because of the present complexity and centralization of advanced AI-relevant semiconductor manufacture.

Article VIII also bans research into the design of more performant or efficient AI chips, which otherwise become substantially more efficient year over year. A data center using more efficient AI chips would be easier to conceal, as these chips would use less electricity for the same or greater performance.

The specific types of research that are restricted would need to be updated in response to changing conditions. One example of such an activity is research into consumer hardware that can efficiently perform AI training activities, if such progress would pose a risk to verification.

Domestic efforts to restrict research could start by focusing on the publication and funding of research. Most researchers want to be law-abiding, gainfully employed citizens; steps that push dangerous AI research outside of accepted social norms would likely be impactful.

The diversity of restricted actions in paragraph 4 addresses a need to ensure that if research activities are split between multiple jurisdictions, the agreement still unambiguously holds each state responsible for prohibiting and preventing the individual activities. Paragraph 4 applies, for example, in the case where a company in one jurisdiction hires an employee in a second who remotely operates chips hosted in a third.

ARTICLE IX — Research Restriction Verification

  1. Each Party creates or empowers a domestic agency with the following responsibilities:

    • (a) Maintain awareness of and relationships with domestic researchers and organizations working on areas adjacent to restricted research, in order to communicate the categories of restricted research established in Article VIII.
    • (b) Impose penalties to deter domestic researchers and organizations from conducting restricted research. These penalties are proportionate to the severity of the violation and are designed to act as a sufficient deterrent. Each Party enacts or amends legal statutes as necessary to enable the imposition of these penalties.
    • (c) Establish secure infrastructure for reporting and containment of inadvertent discoveries meeting the conditions for restricted research. These reports will be shared with the Research Controls division.
  2. To aid in the international verification of research bans, the Research Controls division will develop and implement verification mechanisms.

    • (a) These mechanisms could include but are not limited to:

      • i. Interviews of researchers who have previously worked in restricted research topics, or are presently working in adjacent areas, conducted by the U.S. and China and coordinated by the Research Controls division. These interviews may be overseen by the researcher’s home state to ensure no misconduct.
      • ii. Monitoring of the employment status of researchers who have previously worked in restricted research topics, or are presently working in adjacent areas.
      • iii. Maintaining embedded auditors provided by the U.S. and China in selected high-risk organizations (e.g., projects difficult to distinguish from restricted research, organizations that were previously AI research organizations).
    • (b) Parties, in particular, the U.S. and China, assist in the implementation of these verification mechanisms.

    • (c) The information gained through these verification mechanisms will be compiled into reports for the Executive Council, keeping as much sensitive information confidential as possible to protect the privacy and secrets of individuals and Parties.

Precedent for Article IX

Existing agencies empowered to “maintain awareness of and relationships with domestic researchers and organizations” at risk of developing restricted information, as called for by paragraph 1, subparagraph (a), include the DOE and NNSA, discussed in the precedent section for Article VIII.

Precedent for “monitoring of the employment status of researchers” in high-risk fields, as we suggest in paragraph 2, subparagraph (a)(ii), can be found in the International Science and Technology Center (ISTC).16 Established in 1994, the ISTC was specifically created to reduce nuclear proliferation risks by keeping Soviet nuclear researchers gainfully employed in peaceful activities and connected to the international scientific community. The ISTC also shows the potential of incentives as a complement to penalties for keeping technical experts (who may find themselves unemployed as a result of this agreement) from engaging in restricted research.

Penalties may need to be severe to provide the deterrence indicated in our Article IX, paragraph 1, subparagraph (b). While it may not be directly applicable here, there is precedent for severely punishing the sharing of sensitive data in some contexts. The Enforcement chapter (18) of the 1946 Atomic Energy Act includes fines and imprisonment for unauthorized disclosures. More severe punishments are sometimes levied for other information-disclosure crimes, namely treason.17

When developing secure “infrastructure for reporting and containing inadvertent discoveries of restricted research,” precedent and potentially usable templates may be found in the extensive DOE procedures for handling different categories of sensitive data. The DOE’s Occurrence Reporting and Processing System, as well as the Committee on National Security Systems’s18 instructions for classified information spillage, may also be of use.

The Research Controls division might look to existing practices by the IAEA when developing inspection protocols. Under the framework of the Model Additional Protocol approved in 1997 by the IAEA Board of Governors, states that have made comprehensive safeguard agreements19 allow complementary access inspections that look for undeclared nuclear material. As part of such visits, inspectors may interview operators, analogous to our proposal in paragraph 2, subparagraph (a)(i).

To “protect the privacy and secrets of individuals and parties” when performing verifications, as required by this article’s paragraph 2, subparagraph (c), the Research Controls division might adapt compartmentalization practices of parties’ existing intelligence agencies and multilateral intelligence-sharing agreements. For example, under the “third party rule” or “originator control principle” understood to be commonplace in such arrangements, it is prohibited to disclose shared information to third parties (potentially even oversight bodies) without permission from the originating agency.

Notes on Article IX

To help verify that there is no prohibited AI research happening, Article IX tasks parties with demarcating “areas adjacent to restricted research” and then establishing relationships with the researchers working in these adjacent areas. There are sufficiently few top AI researchers in the world that it may be feasible to track the activities of a significant fraction of them. The technical staff of top AI companies numbers on the order of 5,000 researchers20, and it is commonly believed that a much smaller group is critical to frontier AI development, likely numbering in the hundreds.21 The number of attendees of top AI conferences is estimated to be about 70,000. As higher-end estimates, the number of employees at relevant hardware companies likely numbers around a million22 and the number of people with at least basic technical AI knowledge is likely in the single-digit or tens of millions23. States could interview researchers about their activities and offer asylum and financial incentives for any whistleblowers (see Article X).

While much about current AI development practices happens in the public view, we think legal restrictions would dramatically hamper the efforts of rogue actors to create superintelligent machines.

Monitoring could be extended to researchers and engineers involved in semiconductor design and manufacture if states are willing to incur the extra costs. A more affordable alternative might be to monitor semiconductor manufacturing companies rather than individuals, taking advantage of complex dependencies within the industry which ensure that small groups of rogue individuals would have trouble creating their own chip fabricators.

Parties may be concerned that other parties will violate domestic research bans and hide research efforts from foreign intelligence. Most likely, large efforts involving many researchers and AI-relevant chips would be noticed by a determined intelligence community. But smaller efforts, like developing alternative machine intelligence paradigms, might only involve a few researchers and commonly available hardware. Verifying research controls is a complex and sensitive undertaking requiring ongoing effort and iteration. To facilitate that end, Article X (below) institutes a variety of tools to facilitate intelligence gathering and to protect whistleblowers.

ARTICLE X — Information Consolidation and Challenge Inspections

  1. A key source of information for the coalition is the independent information gathering efforts of Parties. As such, the Information Consolidation division (Article III) will be ready to receive this information. This division coordinates verification and monitoring activities conducted by Parties. Parties conduct monitoring, inspections, and verification using their own capabilities, including intelligence community resources. The CTB establishes standards and protocols for these activities and serves as the central point for receiving declarations and sharing information.

    • (a) The Information Consolidation division takes precautions to protect commercial, industrial, security, and state secrets and other confidential information coming to its knowledge in the implementation of the Agreement, including the maintenance of secure, confidential, and, optionally anonymous reporting channels.

    • (b) For the purpose of providing assurance of compliance with the provisions of this Agreement, each Party uses National Technical Means (NTM) of verification at its disposal in a manner consistent with generally recognized principles of international law.

      • i. Each Party undertakes not to interfere with the National Technical Means of verification of other Parties operating in accordance with the above.
      • ii. Each Party undertakes not to use deliberate concealment measures which impede verification by national technical means of compliance with the provisions of this Agreement.
      • iii. Parties are encouraged, but not obligated, to cooperate in the effort to detect dangerous AI activities in non-Party countries. Parties are encouraged, but not obligated, to support the NTM of Parties directed at non-Parties, as relevant to this Agreement.
  2. A key source of information for the coalition is individuals who provide evidence of dangerous AI activities to the coalition. These individuals are subject to whistleblower protections.

    • (a) This Article establishes protections, incentives, and assistance for individuals ("Covered Whistleblowers") who, in good faith, provide the coalition or a Party with credible information concerning actual, attempted, or planned violations of this Agreement or other activities that pose a serious risk of human extinction, including concealed chips, undeclared data centers, prohibited training or research, evasion of verification, or falsification of declarations. Covered Whistleblowers include employees, contractors, public officials, suppliers, researchers, and other persons with material information, as well as Associated Persons (family members and close associates) who assist or are at risk due to the disclosure.
    • (b) Parties prohibit and prevent retaliation against Covered Whistleblowers and Associated Persons, including but not limited to dismissal, demotion, blacklisting, loss of benefits, harassment, intimidation, threats, civil or criminal actions, visa cancellation, physical violence, imprisonment, restriction of movement, or other adverse measures. Any contractual terms (including non-disclosure or non-disparagement agreements) purporting to limit protected disclosures under this Agreement are void and unenforceable. Mistreatment of whistleblowers constitutes a violation of this Agreement and is handled under Article XI, paragraph 3.
    • (c) The CTB maintains secure, confidential, and, optionally anonymous reporting channels. Parties establish domestic channels interoperable with the CTB system. The CTB and Parties protect the identity of Covered Whistleblowers and Associated Persons and disclose it only when strictly necessary and with protective measures in place. Unauthorized disclosure of protected identities constitutes a violation of this Agreement and is handled under Article XI, paragraph 3.
    • (d) Parties offer asylum or humanitarian protection to Covered Whistleblowers and their families, provide safe-conduct travel documents, and coordinate secure transit.
  3. Challenge inspections of suspected sites may be conducted upon credible information about dangerous AI activities.

    • (a) Parties may request a challenge inspection. The Executive Council, either by request or because of the analysis provided by the Information Consolidation division, will consider the information at hand in order to request additional information, of Parties or non-Parties, or to propose a challenge inspection, or to decide that no further action is warranted.
    • (b) A challenge inspection requires approval by consensus of the Executive Council.
    • (c) Access to a suspected site must be granted by the nation in which the site is present within 24 hours of the Executive Council calling for a challenge inspection. During this time, the site may be surveilled, and any people or vehicles leaving the site may be inspected by officials from a Party.
    • (d) The challenge inspection will be conducted by a team of inspectors who are approved by both the Party being inspected and the Party that requested the inspection. The CTB is responsible for working with Parties to maintain lists of approved inspectors for this purpose.
    • (e) Challenge inspections may be conducted in a given Party’s territory at most 20 times per year, and this limit can be changed by consensus of the Executive Council.
    • (f) Inspectors will take absolute care to protect the sensitive information of the inspected Party, passing along to the Executive Council only what information is pertinent to the Agreement.
  4. U.S. and PRC Independent Verification Efforts

    • (a) The U.S. and PRC each operate an independent verification effort to assess compliance with this Agreement. These verification efforts build upon the pre-existing capabilities of each member’s intelligence community and supplement the work of the Coalition Technical Body.
    • (b) The Coalition Technical Body provides all information it receives or generates to the U.S. and the PRC to support their independent verification efforts. This includes but is not limited to: declarations, reports, monitoring data, inspection results, registers, and any other information relevant to compliance with this Agreement. The CTB does not filter or withhold information from the U.S. and PRC.
Precedent for Article X

We previously discussed precedent for information consolidation with Article VIII, where we cited the existence of intelligence agreements understood to include compartmentalization practices like the “third party rule.” Similar rules can be seen in the IAEA, as in INFCIRC/153 Part 1.5:

…the Agency shall take every precaution to protect commercial and industrial secrets and other confidential information coming to its knowledge in the implementation of the Agreement.

Staff are bound by confidentiality obligations and face criminal penalties for leaks. This matters, because the IAEA has benefited from the intelligence disclosures of participating states, including satellite imagery and documents, as in the case of Iran’s undeclared enrichment activities. Similarly, the IAEA required a special inspection of North Korea’s undeclared plutonium production in response to provided intelligence.

Recognizing the indispensable role of national technical means (NTM — satellite imagery, signals collection, and other remote sensing) in verification of multilateral agreements, our draft agreement borrows language from the ABM treaty limiting anti-ballistic missile systems, in which “each Party shall use national technical means of verification” and “undertakes to not interfere with the national technical means of verification of the other Party.” Similar language can be found in Article XII of the 1987 Intermediate-Range Nuclear Forces Treaty, Article IV of the 1996 Comprehensive Nuclear-Test-Ban Treaty, and throughout the 2010 New START treaty.

As NTM would not be sufficient for detecting all dangerous violations in the case of ASI, we have borrowed features of the IAEA Safeguards framework that encourage internal reporting and provide channels for doing so. But these are hampered by a lack of explicit whistleblower protections; nothing in the NPT or these Safeguards would protect an informant from their government if it decides to retaliate unless that state has applicable domestic protections in place. The provisions for whistleblower protection and asylum in our draft agreement are meant to address this shortcoming.

Recent EU legislation on AI has taken similar measures. The EU AI Act’s Recital 172 explicitly extends the Union’s existing general whistleblower protections to those reporting AI Act infringements.

The 1951 Refugee Convention provides a possible framework for granting asylum to informants, basing qualification on “well-founded fear of being persecuted,” though an amendment or supplemental agreement may be needed to ensure that AI whistleblowing is a legally qualifying cause of persecution.

Asylum for people with sensitive knowledge or expertise was routinely granted in the context of the Cold War and its aftermath. Section 7 of the CIA Act of 1949 provided for admission and permanent residence of up to a hundred defectors and their immediate families per fiscal year if deemed “in the interest of national security or essential to the furtherance of the national intelligence mission.” The Soviet Scientists Immigration Act of 1992 gave up to 750 visas to former Soviet and Baltic States scientists with “expertise in nuclear, chemical, biological or other high technology fields or who are working on nuclear, chemical, biological or other high-technology defense projects.”

The challenge inspections mechanism we lay out in paragraph 3 of this article is modeled after that of Part IX of the CWC:

Each State Party has the right to request an on-site challenge inspection of any facility or location in the territory or in any other place under the jurisdiction or control of any other State Party for the sole purpose of clarifying and resolving any questions concerning possible non-compliance…

The CWC, along with other arms control treaties such as the INF and START I nuclear treaty between the U.S. and USSR, combines NTM with challenge-like inspections to verify compliance.

Notes on Article X

Intelligence Gathering

We expect all parties would make ongoing efforts to independently determine whether any actor is conducting dangerous AI activities, out of interest in their own security. A range of state intelligence gathering activities would supplement and validate monitoring the CTB conducts directly (as described in Articles IV through VII). Towards that end, an Information Consolidation division is vital, and must be trustworthy to receive information from all parties. It will keep sensitive information confidential and secure, and must be sufficiently robust to assure state intelligence services that the risks imposed on their intelligence methods are minimal, and are justified in order to provide needed information to the CTB. Avoiding collecting sensitive information whenever possible, and keeping the collected information in the strictest confidence, minimizes risks of compromise.

Article X also addresses the surveillance of non-signatories, where the need for intelligence is strong.

Article X stops short of imposing an obligation to surveil. It would be unprecedented to mandate the creation of a self-sufficient intelligence gathering capability within the CTB at the required level of capability to give states assurance, and as such, it seems unnecessary in light of the fact that the creation of superintelligence would pose a grave security threat, which means all parties are already strongly incentivized to surveil and monitor any actor with that capability. Thus, the CTB relies primarily on parties to provide key intelligence.

Whistleblower Protections

The overall effectiveness of this agreement relies on parties’ justified confidence that other parties are not undertaking prohibited AI activities. Even with National Technical Means and other intelligence gathering, it may be difficult for states to detect clandestine efforts to develop superintelligence. There are many domains in which it may not be feasible for states to gather intelligence on their rivals, such as efforts conducted inside military facilities. Whistleblowers can serve as an additional source of information, and the possibility of whistleblowing provides further deterrence against non-compliance.

Whistleblowers may be effective because individuals involved in secret violations (e.g., clandestine training runs or AI research) may themselves be concerned about the danger from ASI. This article aims to make it safer and less costly for them to report violations, shifting the personal incentives away from silence and toward disclosure.

Whistleblowers could sound the alarm for violations including:

  • Article IV: Training runs that are unmonitored, exceed thresholds, or use prohibited distributed training methods.
  • Article V: The existence of undeclared chip clusters, the failure to consolidate all covered hardware, or the diversion of chips to secret, unmonitored facilities.
  • Article VI: New manufactured AI chips diverted away from monitoring, or created without mandated security features.
  • Article VIII: Prohibited AI research.

Modifications to the whistleblower clauses could change their efficacy and political viability in various ways. For example, states could offer to financially compensate legitimate whistleblowers to provide additional incentives, but this may be seen as paying citizens to defect on their own countries.

Challenge Inspections

Challenge inspections are a critical function provided by the agreement. Without the credible threat of detection, parties may fear that their rivals would attempt to cheat (despite the lose-lose nature of a race to superintelligence). Intelligence gathering is one method to combat apparent (illusory) incentives to defect.

U.S. and PRC Independent Verification Efforts

The existence of independent verification efforts provides redundancy and enhances the overall assurance that the Agreement is being implemented effectively. We believe the U.S. and the PRC will require independent verification founded on their own analysis, and the agreement and efforts of the CTB support these independent efforts as much as possible.

ARTICLE XI — Dispute Resolution

  1. Any Party ("Concerned Party") may raise concerns regarding the implementation of this Agreement, including concerns about ambiguous situations or possible non-compliance by another Party ("Requested Party"). This includes misuse of Protective Actions (Article XII).

    • (a) The Concerned Party notifies the Requested Party of their concern, while also sharing their concern with the Director-General and Executive Council. The Requested Party will acknowledge this notification within 36 hours, and provide clarification within 5 days.
  2. If the issue is not resolved, the Concerned Party may request that the Executive Council assist in adjudicating and clarifying the concern. This may include the Concerned Party requesting a challenge inspection in accordance with Article X.

    • (a) The Executive Council provides appropriate information in its possession relevant to such a concern.
    • (b) The Executive Council may task the CTB to compile additional documentation, convene closed technical sessions, and recommend resolution measures.
  3. If the Executive Council determines there was a violation of the Agreement, it can take actions to prevent dangerous AI activities or reprimand the Requested Party. These actions may include:

    • (a) Require additional monitoring or restrictions on AI activities
    • (b) Require relinquishment of AI hardware
    • (c) Call for sanctions
    • (d) Recommend Parties take Protective Actions under Article XII
Precedent for Article XI

Our Article XI Dispute Resolution procedures borrow from Articles IX, XII, and XIV of the Chemical Weapons Convention. Article IX of the CWC requires signatories to respond to requests for clarification “as soon as possible, but in any case not later than 10 days after the request.” Given how quickly digital developments can propagate, we chose a 5-day response deadline, but even this figure may need to be adjusted downward.

Our paragraph 2 of this article is modeled after Article XIV of the CWC, which permits its Executive Council to “contribute to the settlement of a dispute by whatever means it deems appropriate, including offering its good offices, calling upon the States Parties to a dispute to start the settlement process of their choice and recommending a time-limit for any agreed procedure.” Parties are also encouraged to refer cases to the International Court of Justice as appropriate.

As in paragraph 3 of our Article XI, the CWC’s Article XII empowers the Executive Council to recommend remedies, including sanctions, “in cases where serious damage to the object and purpose of this Convention may result from activities prohibited under this Convention.” To give force to those recommendations, the CWC’s Council is to “bring the issue, including relevant information and conclusions, to the attention of the United Nations General Assembly and the United Nations Security Council.” Recommendations by our agreement’s Executive Council may be similarly escalated.

Notes on Article XI

The purpose of Article XI is to include a consultation and clarification process to resolve issues that arise between signatories.

Given the pace of AI innovation, determining violations on a reasonable timeline can be challenging. The role of the Executive Council is to adjudicate any concerns raised by any party to the agreement. The CTB has the role of coordinating inspections by experts that have an understanding of cutting-edge AI technologies. The agreement uses an aggressive timeline (measured in hours and days) in the hopes that it is fast enough for parties to wait for rulings before taking Protective Actions (as described in Article XII, below), even despite the rapid pace of technological change in the field of AI. That said, of course no agreement can prevent a party from taking protective actions that they deem necessary to ensure their own security.

ARTICLE XII — Protective Actions

  1. Recognizing that the development of ASI or other Dangerous AI Activities, as laid out in Articles IV through IX, would pose a threat to global security and to the life of all people, it may be necessary for Parties to this Agreement to take drastic actions to prevent such development. The Parties recognize that development of artificial superintelligence (ASI), anywhere on earth, would be a threat to all Parties. Under Article 51 of the United Nations Charter and as longstanding precedent, states have a right to self-defense. Due to the scale and speed of ASI-related threats, self-defense may require pre-emptive actions to prevent the development of ASI.

  2. To prevent the development or deployment of ASI, this Article authorizes tailored Protective Actions. Where there is credible evidence that a State or other actor (whether a Party or a non-Party) is conducting or imminently intends to conduct activities aimed at developing or deploying ASI in violation of Article I, Article IV, Article V, Article VI, Article VII, or Article VIII, a State Party may undertake Protective Actions that are necessary and proportionate to prevent such activities. In recognition of the harms and escalatory nature of Protective Actions, Protective Actions should be used as a last resort. Outside of emergencies and time-sensitive situations, Protective Actions are preceded by other approaches such as, but not limited to:

    • (a) Trade restrictions or economic sanctions
    • (b) Asset restrictions
    • (c) Visa bans
    • (d) Appeal to the UN Security Council for action
  3. Protective Actions may include measures such as cyber operations to sabotage AI development, interdiction or seizure of covered chip clusters, military actions to disable or destroy AI hardware, and physical disablement of specific facilities or assets directly enabling AI development.

  4. Parties minimize collateral harm, including to civilians and essential services, wherever practical, subject to mission requirements.

  5. Protective Actions are strictly limited to preventing ASI development or deployment and are not used as a pretext for territorial acquisition, regime change, resource extraction, or broader military objectives. Permanent occupation or annexation of territory is prohibited. Action will cease upon verification by the coalition that the threat no longer exists.

  6. Each Protective Action is accompanied, at initiation or as soon as security permits, by a public Protective Action Statement that:

    • (a) Explains the protective purpose of the action;
    • (b) Identifies the specific AI-enabling activities and assets targeted;
    • (c) States the conditions for cessation;
    • (d) Commits to cease operations once those conditions are met.
  7. Protective Actions terminate without delay upon any of the following:

    • (a) Coalition certification that the relevant activities have ceased.
    • (b) Verified surrender or destruction of covered chip clusters or ASI-enabling assets, potentially including the establishment of sufficient safeguards to prevent restricted research activities.
    • (c) A determination by the acting Party, communicated to the CTB, that the threat has abated.
  8. Parties do not regard measured Protective Actions taken by another Party under this Article as provocative acts, and do not undertake reprisals or sanctions on that basis. Parties agree that Protective Actions meeting the above requirements are not construed as an act of aggression or justification for the use of force.

  9. The Executive Council reviews each Protective Action for compliance with this Article. If the Executive Council finds that an action was not necessary, proportionate, or properly targeted, actions may be taken under Article XI, paragraph 3.

Precedent for Article XII

The idea that nation-states can take protective actions for their own security is a reality regardless of precedent, but one case of its codification into international law is Chapter VII of the United Nations Charter, which states that the Security Council may take military or non-military measures to maintain international peace and security, when necessary.

The concept of Protective Actions as they appear in the draft above is further grounded in historical precedents where states have acted, individually or collectively, to prevent the development of technologies deemed a threat to international security. These actions range from sanctions to cyber and military strikes.

The international effort to prevent Iran from developing nuclear weapons provides a clear, modern example. The UN Security Council has several times imposed sanctions on Iran due to its nuclear program, most of which were lifted after Iran agreed to limits on said program in the 2015 Joint Comprehensive Plan of Action.

The U.S. and Israel reportedly collaborated on Stuxnet, a highly sophisticated cyberweapon which destroyed many of Iran’s uranium enrichment centrifuges in 2010.

In June 2025, Israel launched airstrikes against many of Iran’s nuclear facilities, and this was followed by U.S. airstrikes nine days later which were partially aimed at disabling the Fordow Uranium Enrichment Plant.

Another historical precedent for Protective Actions is the international response to Iraq’s nuclear noncompliance in the 1990s. Following the 1991 Gulf War, the United Nations Special Commission (UNSCOM) was created to oversee the destruction of Iraq’s weapons of mass destruction. Non-compliance with the UNSCOM inspection regime eventually led to Operation Desert Fox in 1998, a bombing campaign aimed at degrading Iraq’s ability to produce WMDs.

Notes on Article XII

An agreement to prevent the creation of artificial superintelligence might not need to be explicit about the need for Protective Actions against states undertaking ASI development, and instead leave these dynamics implicit, as similar agreements often do. Our draft is explicit because this deterrence regime is core to the effectiveness of the agreement, and clarity around the incentives increases the effectiveness. This explicitness also allows us to include measures that may help prevent Protective Actions being misused, including more thorough description of when these Actions are acceptable.

Once world leaders understand the threat from ASI, they will likely be willing to take action to stop rogue AI development, including limited military interventions. Military actions, such as narrowly targeted airstrikes, should always be treated as a last resort option to prevent the development of ASI, after all other diplomacy has failed. But it is important that they are available as a last resort, in order for the deterrence and compliance regime to hold even towards actors who wrongly perceive recklessly created artificial superintelligence as a technology that would be beneficial rather than destructive.

We stress that any use of force should be targeted at preventing ASI, and should stop once it is clear that the threat has been removed. Article XII aims to make it clear that signatories would not prevent reasonable Protective Actions taken by other parties, but these actions must also be reviewed to ensure that this article is not being abused.

ARTICLE XIII — Coalition Technical Body Reviews

  1. For AI models created via declared training or post-training within the limits of Article IV, the CTB may require evaluations and other tests. These tests will inform whether the thresholds set in Article IV, Article V, Article VII, and Article VIII need to be revised. The methods used for reviews will be determined by the CTB and may be updated.
  2. Evaluations are conducted at CTB facilities or monitored CCCs, by CTB officials. Officials from Parties to the Agreement may be informed which tests are conducted, and the CTB may provide a summary of the test results. Parties will not gain access to AI models they did not train, except when granted access by the model owner, and the CTB will take steps to ensure the security of sensitive information.
  3. The CTB may share detailed information with Parties or the public, if the Director-General deems that this may be necessary to reduce the chance of human extinction from advanced AI.
Precedent for Article XIII

Precedents for tests with oversight are shared with precedents around chip use verification discussed under Article VII, with the missile telemetry sharing protocol of START I being particularly relevant. The added component here in our Article XIII is using collected data to inform recommendations for potential threshold adjustments (which could take place under the precedented mechanisms we discuss with Article XIV).

Regarding the inherent tension between disclosures to the public (paragraph 3) and the information consolidation provisions of our Article X, we note that the Statute of the IAEA’s Article VII confidentiality provision24 has not prevented it from publishing regular and detailed reports on major developments in its associated field and their implications for global security.

Notes on Article XIII

The purpose of Article XIII is to ensure the CTB stays up to date with the state of the field of AI, in case it is advancing. For example, reviewing declared training would allow it to understand the level of AI capabilities that can be reached with different levels of training FLOP. Even with algorithmic research prohibited, there may be progress that cannot be effectively stopped, and the CTB must keep track of it.

Additionally, the CTB has reason to monitor progress in capabilities elicitation. For example, new prompting methods could be discovered that cause an old AI to perform much better on some critical evaluation metric.

We envision CTB reviews that also involve capability evaluations to make sure AIs aren’t getting dangerously capable in specific domains. They could also look at the training data to ensure AIs aren’t being trained for specifically dangerous tasks (like automating AI research), or to test for unexpected AI behavior.

When reviews reveal shifts in the AI development landscape, those shifts could necessitate changes to thresholds relevant to Article IV and Article V, and changes to the definitions of restricted research in Article VIII, with those changes implemented according to the mechanisms in Article III.

ARTICLE XIV — Revision Process

  1. The Executive Council may revise this Agreement as necessary to ensure its purposes are achieved. "Amendments" are considered revisions to the main body and Articles of the Agreement. Under Article III, the CTB may change specific definitions and implementation methods, such as those relevant to Article IV, Article V, Article VI, Article VII, Article VIII, Article IX, and Article X, subject to the Executive Council’s veto power. Fundamental revisions to the purposes of these Articles or to the governance structure require an Amendment by the Executive Council.
  2. The Executive Council may propose amendments to all Parties to the Agreement. The Executive Council shall circulate proposed amendments to all States Parties with an explanation of the rationale and expected effects.
  3. Parties to the Agreement may submit recommendations for amendments to the Executive Council through the Director-General. The Executive Council will consider such recommendations but is not obligated to adopt them.
  4. Amendments proposed by the Executive Council become effective upon consensus of the Executive Council.
  5. Three years after the entry into force of this Agreement, the Executive Council shall convene a review conference to assess the operation of this Agreement with a view to assuring that the purposes of the Preamble and the provisions of the Agreement are being realized. All Parties to the Agreement shall be invited to participate. At intervals of three years thereafter, the Executive Council will convene further review conferences with the same objective.
Precedent for Article XIV

Our agreement is resilient to short-term pressures to relax thresholds or weaken provisions, as it requires consensus by members of the Executive Council to make such changes.

Hard-to-amend (and thus hard-to-weaken) treaties rely on other mechanisms for strengthening as needed. The NPT has never been amended, but has been adapted through the five-yearly Review Conference stipulated in Article VIII, where consensus agreements are made “with a view to assuring that the purposes of the Preamble and the provisions of the Treaty are being realised.”

Similarly, Article XII of the 1975 Biological Weapons Convention relies on its five-yearly Review Conferences to strengthen the treaty through non-binding Confidence-Building Measures, as formal amendments are rare. Our agreement stipulates a three-year conference, as AI has been a field prone to rapid shifts; this period may need to be further shortened.

Article XV of the Chemical Weapons Convention makes a distinction between amendments and administrative or technical changes, with less stringent approval provisions for the latter. Similar language could be added to our draft agreement to provide a level of flexibility in managing future developments in the field of AI.

Article XV of the Outer Space Treaty contains an amendment clause, but the treaty has never been formally amended; instead, new treaties have been negotiated to address emerging space issues. This could be another option for shoring up weaknesses that may become apparent in an AI agreement.

Notes on Article XIV

Article XIV sets out the process to make major revisions to the agreement. These revisions require substantial support from the parties and there is a high bar to make such revisions. By contrast, changes to the details of various categories and restrictions can be made much more easily and rapidly (subject to slower review), as described in Article III, and as is necessitated by the fast pace of change in the field of AI. A careful review process seems warranted given the gravity of the situation, and given the risk that overzealous actors could, if left unchecked, impose misguided restrictions that inconvenience the public for little-to-no benefit.

ARTICLE XV — Withdrawal and Duration

  1. The Agreement shall be of unlimited duration.

  2. Each Party will, in exercising its national sovereignty, have the right to withdraw from the Agreement if it decides that extraordinary events, related to the subject matter of this Agreement, have jeopardized the supreme interests of its country. It shall give notice of such withdrawal to the CTB 12 months in advance.

  3. During this 12-month period, the withdrawing state shall cooperate with CTB and Executive Council member efforts to certify that after withdrawal, the withdrawing state will be unable to develop, train, post-train, or deploy dangerous AI systems, including ASI or systems above the Agreement thresholds. Withdrawing states acknowledge that such cooperation aids the CTB and Parties in avoiding the use of Article XII.

    • (a) In particular, the withdrawing state, under CTB and Executive Council member oversight, will remove all covered chip clusters and ASI-enabling assets (e.g., advanced computer chip manufacturing equipment) from its territory to Executive Council-approved control or render them permanently inoperable (as described in Article V).
  4. Nothing in this Article limits the applicability of Article XII. A State that has withdrawn (and is therefore a non-Party) remains subject to Protective Actions if credible evidence indicates activities aimed at ASI development or deployment.

Precedent for Article XV

It is common for treaties to lack expiration dates. The first paragraph of Article XVI of the CWC states “This Convention shall be of unlimited duration.”

Agreements of unlimited duration do not necessarily last forever.25 But they do typically provide a mechanism for withdrawal, usually with a required period of notice and other stipulations that might let it leave in a manner less concerning to the remaining parties. Article XVI of the CWC allows for a party to withdraw “if it decides that extraordinary events, related to the subject-matter of this Convention, have jeopardized the supreme interests of its Country.” The withdrawing country must give 90 days notice. Article XVI of the Outer Space Treaty requires one year notice for withdrawal.

Our agreement expects 12 months’ notice from departees, allowing ample time for assisting with the assurance-providing measures in Paragraph 3. Our intent with these measures (which go beyond what we readily find in the historical record of withdrawal provisions) is to reduce the potential need for protective actions against the withdrawing Party, as no Party or non-Party can be allowed to create ASI or weaken the world’s ability to prevent its creation.

Historical precedent for a withdrawn party remaining subject to protective actions is found in the case of United Nations Security Council Resolution 1718, which imposed sanctions against North Korea after its 2006 nuclear test, despite North Korea’s previous withdrawal from the NPT.

Notes on Article XV

Given the dangers of ASI research and development, as well as the risk that if one country decides to withdraw from the agreement and race to superintelligence then others might follow, the agreement needs barriers to withdrawal.

In practice, this is challenging. North Korea, for example, withdrew from the NPT to continue its nuclear proliferation activities, even at the cost of UN Security Council resolutions and associated sanctions. The consequences did not prove sufficient to cause North Korea to stop its proliferation activities.

If nations wish to withdraw from the agreement, our wording makes it clear that, in the eyes of all parties, they forgo the right to AI infrastructure, and that they would be subject to Article XII Protective Actions if they engage in dangerous AI activities. Any further negotiation around the ASI issue — e.g., to avoid Protective Actions — would have to be negotiated separately by interested parties.

Parties concerned about withdrawals could include mechanisms to make withdrawal more difficult. For example, both U.S. and Chinese officials could agree to install mutual killswitches inside covered chip clusters, allowing either party to permanently shut off the other’s clusters. Alternatively, parties could adopt a multilateral licensing regime in which all new AI chips must be fabricated with hardware locks that require approval from multiple parties to continue operation, so that if a country withdrew from the agreement, others could stop approving their licenses and incapacitate their chips. Another option involves moving key AI infrastructure into third-party countries where the infrastructure could be confiscated or destroyed if a party withdrew from the agreement. Our draft sticks to minimal deterrence methods, but many other methods are available (or could be made available with a little technological investment).


Footnotes

  1. This is the case with nuclear weapons agreements, where separate treaties establish the IAEA (1956, by the Conference on the Statute of the International Atomic Energy Agency, hosted at the Headquarters of the United Nations), the NPT (1970, through negotiations in the United Nations Eighteen Nation Committee on Disarmament), and the arms control agreements like the START treaty (1991, following nine years of intermittent negotiation between the U.S. and the Soviet Union).
  2. The NPT is generally credited with keeping the number of nuclear states lower than it might have been, but acquisitions by non-signatories (India, Pakistan, Israel) and former signatories (North Korea) have still occurred. Any non-signatory creating even a single ASI is comparable in danger to a mass thermonuclear exchange, and must be treated accordingly.
  3. The Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons Which May Be Deemed to Be Excessively Injurious or to Have Indiscriminate Effects, commonly called the CCW, entered into force in 1983. As of 2024, its 128 parties commit to protect combatants and non-combatants from unnecessary and egregious suffering by restricting various categories of weapons.
  4. The U.S. and USSR had already agreed to stop other kinds of nuclear weapons tests in 1963 with the Treaty Banning Nuclear Weapon Tests in the Atmosphere, in Outer Space and Under Water, commonly called the Limited Test Ban Treaty (LTBT) or Test Ban Treaty.
  5. The Treaty Between the British Empire, France, Italy, Japan, and the United States of America for the Limitation of Naval Armament (the Washington Naval Treaty) lists ships to be scrapped by name in a table (Section II).
  6. The Strategic Arms Reduction Treaty was signed in 1991 and entered force in 1994. Signatories were each barred from deploying more than 6,000 nuclear warheads on a total of 1,600 intercontinental ballistic missiles and bombers.
  7. The Strategic Arms Limitation Talks (SALT) commenced in 1969 between the U.S. and USSR, producing the SALT I treaty, signed in 1972, which froze the number of strategic ballistic missile launchers and regulated the addition of new submarine-launched ballistic missiles, among other restrictions.
  8. The 1972 Anti-Ballistic Missile Treaty (ABM) grew out of the original SALT talks, and limited each party to two anti-ballistic complexes each (later, just one) with restrictions on their armament and tracking capabilities.
  9. With the 1987 Intermediate-Range Nuclear Forces Treaty (INF), the U.S. and USSR agreed to ban most nuclear delivery systems with ranges in between those of battlefield and intercontinental systems. (Given the short warning time strikes from such systems would afford, they were seen more as destabilizing offensive systems than as defensive assets.)
  10. The Food Safety and Inspection Service (FSIS) is an agency of the U.S. Department of Agriculture formed in 1977.
  11. Another key consideration for chip use verification measures is security and privacy. Parties will want to ensure that the CTB only has access to the information it needs for verification without also having access to sensitive data on the chips (such as military secrets or sensitive user data). Therefore, the verification methods used would need to be made secure and would be narrowly scoped when possible.
  12. The 1946 Atomic Energy Act was later augmented by the Atomic Energy Act of 1954 with the goal of allowing for a civilian nuclear industry, which required allowing some Restricted Data to be shared with private companies.
  13. The 1979 case of United States v. The Progressive, in which a newspaper intended to reveal the “secret” of the hydrogen bomb, might have given the U.S. Supreme Court an opportunity to rule on whether the “born secret” doctrine violates the First Amendment’s protections on speech, if the government hadn’t dropped the case as moot.
  14. An arm of the U.S. Department of Commerce.
  15. Hundreds of such orders have been placed on cryptography-related patents over the decades.
  16. The International Science and Technology Center grew out of the 1991 Nunn-Lugar Cooperative Threat Reduction program, a U.S. initiative to secure and dismantle WMDs and their associated infrastructure in former Soviet states.
  17. Parties to our agreement may wish to explore expanding the concept of crimes against humanity (codified in the 1998 Rome Statute of the International Criminal Court) to cases where a researcher deliberately seeks to develop ASI at the expense of the people of Earth.
  18. The Committee on National Security Systems (CNSS) is a U.S. intergovernmental organization that sets security policies for government information systems.
  19. 144 States, as of June 2025
  20. OpenAI’s GPT-5 announcement lists 470 contributors. Google’s Gemini 1.5 technical report lists 1135 contributors. The Llama 3 paper lists 559 authors. The DeepSeek-V3 paper lists 199 authors. The Qwen3 paper lists 177 total contributors. The Kimi k2 paper lists 168 authors. The sum of these numbers is 2,708. Other frontier AI companies such as Anthropic and xAI do not provide sufficient details about the number of technical contributors, to our knowledge. There are other companies that may have sufficient AI talent, therefore we conservatively estimate that the total number of researchers at top AI companies is on the order of 5,000.
  21. In a 2025 interview, David Luan, head of Amazon’s AGI research lab, estimated the number of people he would trust “with a giant dollar amount of compute” to develop a frontier model at “sub-150.”
  22. TSMC employee count: 84,000 in 2025. Intel employee count: 125,000 in 2023. Samsung employee count: 263,000 in 2024. SMIC employee count: 20,000 in 2023. NVIDIA employee count: 36,000 in 2025. AMD employee count: 26,000 in 2023. Huawei employee count: 208,000 in 2024. Google TPU division: unknown. ASML employee count: 44,000 in 2024. SK Hynix employee count: 47,000 in 2024. Micron employee count: 43,000 in 2023. The sum of these numbers is 896,000. So the total number of employees at the most relevant AI hardware companies is likely around one million, though the core technical staff are probably a small subset of this and the number of crucial researchers may only be a few thousand.
  23. In April 2025, the popular platform for sharing AI models and datasets HuggingFace had 8 million users. The number of students who have taken Andrew Ng’s Machine Learning course is about 4.8 million. The number of developers using GitHub (broader than just AI) was around 100 million in 2023, and the total number of professional software developers in the world is estimated at 47 million in 2025.
  24. VII.F states that “[…] subject to their responsibilities to the Agency, [the Director General and the staff] shall not disclose any industrial secret or other confidential information coming to their knowledge by reason of their official duties for the Agency”
  25. Sometimes they are superseded by other treaties. This was the case for the 1947 General Agreement on Tariffs and Trade (GATT); it was superseded by the 1994 Marrakesh agreement, which incorporated the rules from GATT but established the World Trade Organization (WTO) to replace GATT’s institutional structure. Treaties of unlimited duration also sometimes end when parties withdraw in a manner that makes the treaty ineffective. For example, the U.S. and USSR initially agreed to the 1987 Intermediate-Range Nuclear Forces (INF) Treaty for an unlimited duration, but the U.S. withdrew in 2019 citing Russian non-compliance, and Russia later announced it would no longer abide by the treaty in 2025.

日本語訳を読む