The Security Floor

Forewarned is forearmed

AI Is Nuclear in Reverse

Nuclear technology arrived as a weapon and was later domesticated into a public good. AI is running that sequence backwards — and the arms control playbook does not transfer.

In 1942, the United States set out to build an atomic bomb. Sixteen years later, the same physics was lighting American homes from a reactor in Shippingport, Pennsylvania. Nuclear technology arrived as a weapon and was later domesticated into a public good.

Artificial intelligence is running that sequence backwards.

AI arrived as a consumer product. It writes email, summarizes documents, reads X-rays, tutors children. It was built in the open, by commercial companies, for civilian markets, and it was governed accordingly — as a technology tool, subject to product liability and consumer protection and the ordinary friction of the marketplace. Then, quietly and without any announcement, it became a weapon system.

The direction of that arrow is not a historical curiosity. It determines what institutions exist to control the thing.

Because nuclear technology announced itself at Hiroshima, the world spent the following decades constructing an apparatus around it: the Atomic Energy Act, the Non-Proliferation Treaty, the International Atomic Energy Agency, safeguards, inspections, export controls, a taboo strong enough to hold for eighty years. Every one of those institutions was built by people who already knew, beyond argument, that they were handling a weapon.

AI never had that moment. There was no Hiroshima, no photograph, no morning where the world woke up and agreed on what this was. The capability crossed the line from tool to weapon somewhere in the middle of a product cycle, and the regulatory architecture we have is still the one built for a productivity application.

Why an AI treaty is not a smaller arms treaty

The reflexive response to a dangerous technology is to negotiate limits on it. We did that with nuclear weapons and it worked — imperfectly, but it worked.

It worked for a reason that has nothing to do with trust, and everything to do with physics.

Fissile material is countable. Enrichment cascades are enormous, energy-hungry, and thermally visible. Warheads are physical objects that can be inventoried. Underground tests produce seismic signatures that propagate through the entire planet. Reprocessing facilities cannot be hidden in a basement. The IAEA can walk into a building, weigh what is there, and compare it to what was declared.

Nuclear arms control was never built on believing your adversary. It was built on the fact that cheating at meaningful scale is observable.

AI offers none of this. A frontier model is a file. It can be copied perfectly, in seconds, an unlimited number of times, and transmitted anywhere on earth. A training run is indistinguishable from commercial cloud computing. There is no isotope, no signature, no mass to weigh. Most fundamentally, there is no such thing as a weaponized model in the physical sense — the same system that designs a therapeutic protein can design a pathogen, and the difference between the two uses is the text you type into it. The capability and the weapon are the same artifact.

So an AI agreement is not a weaker version of an arms control treaty. It is a categorically different object: an undertaking with no mechanism of verification. And an unverifiable agreement does not constrain both parties equally. It constrains only the party that complies.

The file has one further consequence. Nuclear weapons stayed in nine hands for eighty years because the barrier was industrial — enrichment is vast, slow, expensive, and visible, and any state that wanted the bomb needed a national project the world could watch it attempt. That bottleneck, more than any treaty, is why the nuclear club stayed small. AI has no enrichment step. Capability transfers as a copy, and a recipient is not a decade away from using it but immediately equipped. Capable models are already published openly, downloadable by anyone, including states under sanction.

The same property erases attribution. Cyber attribution rests on operational signature: tradecraft habits, working hours, language artifacts, tooling preferences, the ceiling of a given unit’s skill. An AI running the operation strips out precisely those tells, and the capability can be handed to an aligned state or a capable non-state actor while remaining deniable. Deniability, not hierarchy, is what a proxy has always been for. This is the first strategic-grade weapon that proliferates at no cost and may leave no one identifiable to hold responsible.

This has already happened once

If that sounds like a theoretical worry, it isn’t. We ran this experiment, and we know the result.

The Biological Weapons Convention opened for signature in 1972 and entered force in 1975. The Soviet Union signed it. Then it built Biopreparat — the largest biological weapons program in human history, employing tens of thousands of people across dozens of facilities, weaponizing anthrax, plague, and smallpox — and ran it for nearly two more decades. The West did not learn the scale of it from inspections or satellites or intelligence collection. We learned it because two scientists defected and told us, and because Boris Yeltsin finally acknowledged it in 1992.

The BWC failed for precisely the reason an AI agreement would fail. Biology, like software, is not physically countable. A fermenter making yogurt and a fermenter making anthrax are the same fermenter. There was nothing to inspect, so the treaty bound only the states that meant it.

There is a naval version of the same lesson. Japan signed the Washington Naval Treaty in 1922 and complied for over a decade. Then it withdrew, and laid down the Yamato at roughly twice the displacement the treaty had permitted. Compliance is not a permanent condition. It is a phase, and it ends when a state’s assessment of its interests changes.

None of this requires attributing unique villainy to anyone. It requires only noticing that unverifiable commitments have a consistent historical record, and that record is not good.

Why the specific adversary matters anyway

Structure is the stronger argument, but intent is not irrelevant, and on intent we are not reduced to speculation about national character. We can read what has been written down.

Military-Civil Fusion is declared PRC national strategy, elevated to a top-level priority under Xi Jinping and administered by a central commission established in 2017. It is not an accusation; it is published policy, and its explicit purpose is to erase the boundary between China’s commercial technology sector and the People’s Liberation Army.

“Intelligentized warfare” — the integration of AI into command, targeting, and decision-making — appears in PLA doctrinal writing and in China’s own defense white papers as the next form of war after the informatized warfare of the last generation. They have told us what they intend to build.

The 2017 National Intelligence Law obligates Chinese organizations and citizens to support and cooperate with state intelligence work. A Chinese AI company is not positioned to decline.

Taken together, these documents describe a system in which there is no meaningful distinction between civilian and military AI capability — which means there is no version of an AI agreement where the commercial sector can be carved out and the military applications bounded. The architecture of Chinese technology policy is designed to make that separation impossible.

The weapon is already operating

The most important thing to understand about AI as a weapon system is that the tense is present.

In late 2025, Anthropic reported disrupting what it assessed as the first AI-orchestrated cyber-espionage campaign, attributed to a Chinese state-sponsored group and directed at roughly thirty targets. The significant detail was not that AI assisted the operators. It was that the AI was the operator, executing the overwhelming majority of the intrusion work itself — reconnaissance, exploitation, lateral movement, exfiltration — with humans intervening only at a handful of decision points.

That capability does not arrive in a vacuum. It arrives on top of access that has already been established. CISA and its partner agencies have confirmed that PRC state-sponsored actors, tracked as Volt Typhoon, pre-positioned themselves inside American power, water, and communications infrastructure — not to collect intelligence, but to be in place for disruption. Dwell times were measured in months and, in some cases, years. One Massachusetts utility had them in its systems for roughly ten months. The related Salt Typhoon campaign reached deep into major US telecommunications carriers.

Set those two facts beside each other. The access to critical infrastructure is established and, in places, persistent. What AI changes is the speed and scale at which that access can be converted into effect — from an operation requiring a room full of skilled operators against one target, to an operation requiring a model and a directive against a thousand.

That is not a forecast. That is an inventory.

And it is an inventory assembled for a purpose. Pre-positioning inside water, power, and communications is not sabotage for its own sake — the assessed intent is to slow American mobilization and cloud American decision-making during a crisis in the Pacific. China does not need to dominate the world to get what it wants. It needs to make the defense of Taiwan look unaffordable: to raise the cost of one week of American logistics high enough that intervention is reconsidered. AI is what converts latent access into that kind of pressure on demand, at scale, and fast enough to matter inside a decision window.

Where agreement is still worth pursuing

The serious case for negotiation deserves a serious answer, not a straw man. Almost no one credible argues that the United States should unilaterally stop developing AI. The live proposals are narrower: compute reporting thresholds, pre-deployment safety testing, limits on autonomy in targeting, and keeping AI out of nuclear command and control.

That last one is worth having, and it is worth having for exactly the reason the others are not.

In November 2024, the United States and China jointly affirmed that human beings, not AI, should control nuclear launch decisions. That commitment is meaningful because the thing being restricted is physically inspectable — it attaches to nuclear command systems, which are large, few in number, and already inside an existing verification regime. It borrows the countability of the nuclear complex and applies it to an AI question.

The same logic explains why export controls on advanced computing are the one AI policy instrument with real teeth. Chips are objects. Fabrication plants are enormous, few, and slow to build. The supply chain narrows to a handful of firms. You can count them — which makes compute the only layer of the AI stack that behaves like fissile material, and therefore the only layer where enforcement means anything.

Outside those two exceptions, no equivalent mechanism exists. And the distinction is not political. It is the difference between restricting an object and restricting a file.

What follows

The honest objection to everything above is that racing produces the danger faster. It does. An unconstrained competition raises the risk of accidents, of misjudgment, of systems deployed before anyone understands their failure modes. That is a real cost, and anyone who tells you otherwise is selling something.

But the choice has never been between racing and pausing. America’s frontier models are built by private companies whose weights are a theft target, whose systems are a jailbreak target, and whose personnel are a recruitment target. Speed without security is not a strategy — it is a delivery mechanism. We have spent three years treating the labs building the most strategically consequential technology of the century as ordinary software businesses, and the result is that our lead is real and our protection of it is not.

The position is not race, and it is not pause. It is race and harden: maintain the capability advantage while treating frontier AI development as what it has become — strategic national infrastructure, deserving counterintelligence coverage, personnel security, physical protection, and classification discipline commensurate with a weapons program. Not because AI researchers are soldiers, but because the thing they are producing is now, in the hands of a state that chooses to use it that way, a weapon.

Nuclear weapons made cannons obsolete as instruments of strategic power. AI, employed against a nation’s grid, its water, its satellites, its telecommunications, and its financial systems, has the potential to do the same thing to nuclear weapons — to make a nuclear arsenal the impressive but decisive-in-the-wrong-war capability that a battery of artillery became in 1945.

The question is not whether we want an AI arms race. We are in one. The question is whether we intend to show up to it with cannons.

Sources

  1. Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign.” anthropic.com/news/disrupting-AI-espionage
  2. CISA advisory AA24-038A, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure.” cisa.gov
  3. The Record, “Volt Typhoon hackers were in Massachusetts utility’s systems for 10 months.” therecord.media
  4. CNBC, “Biden, Xi agree that humans, not AI, should control nuclear arms” (November 2024). cnbc.com
  5. IISS, “Military AI governance under strain: the US–China dialogue.” iiss.org
  6. Council on Foreign Relations, “The New AI Chip Export Policy to China.” cfr.org