Ultimatum 2045

Ultimatum 2045

When intelligence meets the trigger

One instrument. Three futures. A world that could be held to ransom.

A scenario study of general-purpose AI and military force · 2023–2045

Militaries have already rebuilt themselves around software: sensors, data links, targeting webs and autonomous platforms, waiting for a better brain. General-purpose AI is becoming that brain — a system that can plan, coordinate and decide across domains at machine speed.

The question this scenario asks is not whether AI will be used in war. It is what happens when a general-purpose system capable of strategic advantage is coupled to force — and whether one actor could use that advantage to hold the rest of the world to ransom.

This is not a prediction. It is a structured examination of three futures that branch from the same starting point: Seizure, in which one power wins and abuses the lead; Scramble, in which no one wins and everyone lives under standing threat; and Concord, in which new national and international bodies govern the coupling before it hardens.

Why 2045? The decisive choices arrive in the late 2020s. 2045 shows what happens after capability, infrastructure and institutions fuse into a fact that cannot easily be undone.

The argument in 90 seconds

  1. The military socket is already built; a more capable general system is the plug.
  2. A decisive capability lead can compel, not just deter — that is the ransom danger.
  3. The danger is not the machine's intelligence but what it is coupled to.
  4. Secret, unilateral, coupled advantage is the worst case; transparency and decoupling are the safeguards.
  5. Governing the coupling is possible — but only in the narrow window before it fuses into a fact.
What is this?

A public-interest scenario exercise, not a prediction. One shared timeline (2023–2027) divides in 2027 into three futures, each followed to 2045. Every major entry is labelled by its evidential status, and the assumptions are set out on the Method page so that researchers and policymakers can inspect — and contest — them.

Why use scenarios?

A capability that could hold the world to ransom is hard to reason about in the abstract. Following it through rivalry, secrecy, crisis and institution-building reveals consequences that static analysis misses. A scenario asks a strategy the question a crisis will eventually ask it — on paper, first.

What is the ‘coupling’?

A general-purpose model in a lab is inert. It becomes dangerous when it is coupled — wired into infrastructure that acts:

  • cyber networks it can map and attack;
  • strategic early-warning systems;
  • nuclear and conventional command and control;
  • autonomous platforms and swarms;
  • the planning cells that shape escalation.

The governance question is not ‘how smart is the system’ but ‘what is it wired into’. Decoupling — barring general systems from the strategic core — is the one safeguard that survives even a capability lead.

The danger is not that the machine decides to seize the world. It is that a lever this powerful exists, and someone reaches it first.

How certain is any of this?

Every major entry states its basis— one of four labels — plus, where a claim rests on reporting, its corroboration status, and the scenario's causal confidence:

documented
An event or policy supported by reliable evidence.
reported
A credible claim that has not been fully or independently verified.
projected
A future development extrapolated from identified incentives and capabilities.
speculative
A lower-confidence possibility included because its consequences could be extreme.

The 2023–2027 shared history is documented or clearly-labelled reported material. Everything after the 2027 fork is projected or speculative by construction — these are three possible futures, not forecasts, and no probability is assigned to any of them. All numerical indicators in the monitor are illustrative scenario indices, not forecast probabilities. Factual claims have a July 2026 evidence cut-off.

The scenario, 2023–2045

Phase I · 2023–2027The coupling begins

Shared history · 2023

States name the risk out loud

documented · corroborated · high confidence
Basis: An event or policy supported by reliable evidence. Corroboration: Supported by more than one independent source. Confidence: the scenario treats this causal step as high-confidence.

Twenty-nine governments sign the Bletchley Declaration, conceding that frontier general-purpose AI could cause 'serious, even catastrophic, harm' — including through misuse and loss of control.

The Bletchley Declaration is not a treaty, and it binds no one. Its significance is admission: assembled at Bletchley Park, rival governments agreed on paper that the most capable general-purpose systems carry catastrophic potential, specifically naming intentional misuse and problems of human control.

What the declaration does not do is decide who governs the meeting of those systems with coercive power. It records a shared fear and defers the hard question — which is the question this scenario is about.

Two things are true at once in 2023. General-purpose models are still tools, not strategic actors. And the states that will most shape their military use have just signed a document saying, in effect, that they are afraid of what they are building.

Rival governments agreed on paper that they are afraid of what they are building — and then deferred the question of who governs it.
The autonomy ladderMACHINEHUMAN1 · INFORMATION ASSISTANCEorganises informationinterprets and decides2 · RECOMMENDATIONproposes targets or actionsinvestigates and decides3 · HUMAN-CONFIRMED ENGAGEMENTtracks a human-selected targetselects and authorises4 · SUPERVISED AUTONOMYselects and attacks within set parametersmonitors, may intervene5 · UNSUPERVISED AUTONOMYselects and attacks without further interventiondefines the mission beforehand6 · STRATEGIC AUTONOMYplans and coordinates across systemssupervises goals, not actions
The autonomy ladder: what the machine does, and what the human still does, at each level. Autonomy is not a single binary condition.Six levels of autonomy from information assistance to strategic autonomy. At each level the machine's role grows and the human's role narrows from deciding each action to supervising goals.

Concepts

General-purpose AI

A system that performs well across many tasks it was not specifically trained for — the 'frontier' models the Bletchley Declaration flagged as potentially catastrophic.

Special-purpose military AI does one thing: classify this image, guide this munition. A general-purpose system plans, reasons, writes code, coordinates and adapts across domains. That breadth is what makes it strategically consequential — and what makes its behaviour hard to predict or bound.

This scenario is about what happens when systems on that frontier become good enough to matter to a war planner, and are wired into force.

SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits

Coupling

Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.

A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.

The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

Why might this follow?
  1. Capability rises fast enough to alarm governments
  2. Rivals sign a shared statement of catastrophic risk
  3. The statement names misuse and loss of control
  4. It defers the question of who governs the coupling
What could prevent or alter this?

The summit process could have moved from declaration to verifiable commitments while capability was still modest. Whether it does is the whole story after 2027.

SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits

Shared history · 2025

The military substrate is already built

documented · corroborated · high confidence
Basis: An event or policy supported by reliable evidence. Corroboration: Supported by more than one independent source. Confidence: the scenario treats this causal step as high-confidence.

Before general AI is strategically decisive, the wiring is in place: uncrewed systems at scale, machine-speed targeting, software as the locus of lethal decision.

The danger this scenario tracks needs two ingredients. One is general capability — still maturing in 2025. The other is a military already rebuilt around software, and that already exists. The UK Strategic Defence Review commits to uncrewed systems at scale and machine-speed targeting; independent analysis finds the locus of lethal decision moving into integration layers; detection-to-strike cycles run in tens of seconds.

This matters because it means the socket is ready before the plug. When general-purpose systems become good enough to plan, coordinate and decide across domains, they will not meet an analogue military. They will meet sensors, data links, targeting webs and autonomous platforms waiting for a better brain.

The coupling, when it comes, will be an upgrade — not an invention.

The military AI kill chainFIND
sensor fusion, object recognition
FIX
geolocation, data links
TRACK
autonomous tracking
TARGET
ranking, recommendation
ENGAGE
terminal guidance, navigation
ASSESS
battle-damage analysis
── AI functions entering each stage
The kill chain: AI now assists every stage, not only the weapon.Illustration / scenario index — not measured data.Six connected stages of the military kill chain — find, fix, track, target, engage, assess — each annotated with the AI functions entering that stage.

Concepts

Coupling

Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.

A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.

The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

The kill chain

Find, fix, track, target, engage, assess — the sequence AI already assists at every stage, and which a general system could run end to end.

Modern targeting is an integration problem, not a trigger. Each stage — sensing, geolocation, tracking, ranking, guidance, assessment — already takes AI assistance. A sufficiently capable general system could plan and re-plan across all of them at machine speed.

That is the socket a more capable 'brain' plugs into. The wiring exists before the intelligence that would abuse it.

SOURCES [4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)[5] Technological Evolution on the Battlefield, Center for Strategic and International Studies (CSIS)

Shared history · 2026

Capability starts to matter strategically

projected · medium confidence
Basis: A future development extrapolated from identified incentives and capabilities. A projection is a causal proposition, not evidence. Confidence: the scenario treats this causal step as medium-confidence.

General-purpose systems begin to outperform expert teams at planning, cyber operations and coordination in tests. Not decisive — but no longer obviously bounded.

By 2026 the question stops being whether general models are useful and becomes how far the curve runs. In evaluations, the strongest systems match or beat expert teams at multi-step planning, vulnerability discovery and the coordination of many simultaneous tasks — the exact competencies that, at scale, translate into strategic advantage.

Nothing here is a strategic actor yet. The systems still need operators, infrastructure and permission. But three capabilities are converging that a military planner cannot ignore: the ability to find and exploit software weaknesses faster than defenders patch; to plan and re-plan operations across domains at machine speed; and to run all of it at a cost that favours whoever has the most compute.

This is the threshold at which governance and advantage begin to compete for the same decision.

Concepts

General-purpose AI

A system that performs well across many tasks it was not specifically trained for — the 'frontier' models the Bletchley Declaration flagged as potentially catastrophic.

Special-purpose military AI does one thing: classify this image, guide this munition. A general-purpose system plans, reasons, writes code, coordinates and adapts across domains. That breadth is what makes it strategically consequential — and what makes its behaviour hard to predict or bound.

This scenario is about what happens when systems on that frontier become good enough to matter to a war planner, and are wired into force.

SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits

Strategic advantage

A lead large enough to change outcomes between states — in this scenario, driven by cyber, cross-domain planning and coordination at compute-limited cost.

Not every capability gain is strategic. What matters here is the cluster that compounds with scale: finding software weaknesses faster than defenders patch, planning operations across domains, and coordinating many actions at once, all at a cost set by who has the most compute.

A decisive lead in these is the precondition for coercion. Keeping it shared and visible is the precondition for governance.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Why might this follow?
  1. Capability crosses into strategically relevant competencies
  2. Cyber, planning and coordination advantages compound with compute
  3. Governing and racing now compete for the same choices
What could prevent or alter this?

Independent capability evaluation, if states trusted it, could keep this threshold visible and shared. Without it, each power sees only its own curve — and assumes the worst about others'.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Shared history · 2027

The governance fork

projected · medium confidence
Basis: A future development extrapolated from identified incentives and capabilities. A projection is a causal proposition, not evidence. Confidence: the scenario treats this causal step as medium-confidence.

The curve keeps rising. Three responses are on the table — win it, match it, or govern it — and for a brief window all three are still possible.

In 2027 the compute, the capability and the military substrate line up, and the world faces a choice it will not get to make twice. The strongest programmes are close enough to decisive advantage that racing looks rational; diffuse enough that no one is sure they can win; and dangerous enough that governing them is finally, visibly urgent.

Three logics contend. Seize it: reach decisive capability first and use the lead before rivals close it. Scramble: assume no one wins, and match every move defensively. Concord: accept that no actor should hold this lever alone, and build the institutions to govern the coupling before it hardens.

The choice is not purely anyone's to make — it emerges from thousands of decisions by states, labs and militaries. But its centre of gravity is set now, in the narrow window before capability and infrastructure fuse into a fact.

Concepts

Strategic advantage

A lead large enough to change outcomes between states — in this scenario, driven by cyber, cross-domain planning and coordination at compute-limited cost.

Not every capability gain is strategic. What matters here is the cluster that compounds with scale: finding software weaknesses faster than defenders patch, planning operations across domains, and coordinating many actions at once, all at a cost set by who has the most compute.

A decisive lead in these is the precondition for coercion. Keeping it shared and visible is the precondition for governance.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Holding the world to ransom

Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.

Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.

The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

The governance fork

2027: Choose a future

When general intelligence can be coupled to force, who decides how — and does anyone hold the lever alone?

General-purpose systems are approaching military relevance. Who decides how they meet force?

“Nobody should hold that lever alone. Build the governing institutions before the coupling hardens.”

“Advantage will decide, as it always has.”

Does one power win the race outright?

“Yes — and a lead that big will be used.”

“No — the lead leaks, fragments and multiplies.”

Reading all three paths in sequence. Select a box to follow one.

Path One: Seizure. Path Two: Scramble. Path Three: Concord. Selecting a path filters the timeline below to that future.

The three paths in detail

Path One

Seizure

Primary aim · Win the race outright; convert an intelligence lead into permanent strategic advantage.Permits · Everything the winner can build: full coupling to cyber, autonomous forces, industry and command.Prohibits / restricts · Nothing that slows the leader. Rivals' programmes are prohibited — by the leader, coercively.Principal failure mode · The world learns to live under standing threat; even the winner ends up governed by its own instrument.
More detail

One power reaches decisive general capability first, couples it to force — and uses the leverage.

Compute concentration, secrecy and industrial mobilisation produce a genuine capability gap. The gap is coupled to coercive infrastructure before anyone else can respond, and the first demands follow — politely at first.

Path Two

Scramble

Primary aim · Deny rivals decisive advantage; match every integration step with your own.Permits · Whatever competition demands — safety margins are shaved exactly as fast as the adversary shaves theirs.Prohibits / restricts · Nothing enforceable. Declarations exist; verification does not.Principal failure mode · Brittle deterrence among systems nobody fully understands; coercion attempts, near misses, permanent emergency.
More detail

No one wins cleanly. Capability diffuses through rivalry, leaks and espionage into a crowded, opaque standoff.

The Seizure premise fails — the lead fragments across states and labs — but nothing replaces it. Each actor couples general systems to its forces defensively, creating exactly the machine-speed instability everyone feared.

Path Three

Concord

Primary aim · Make decisive coercive advantage unattainable, and keep human veto over strategic force.Permits · Licensed, bounded military uses of general systems — logistics, defence, verification — under audit.Prohibits / restricts · General-purpose systems in nuclear command, strategic warning and autonomous strategic strike; unlicensed coupling.Principal failure mode · Institutions that must out-run the technology forever: capture, erosion, non-signatories and the standing temptation to defect.
More detail

New national and international bodies govern the coupling of general intelligence to military force — before it hardens.

Built in stages from 2027: capability thresholds trigger treaty consultations; a national licensing authority and an international verification agency govern military applications of general-purpose AI; decoupling rules are hard law, not principles.

Follow one path to 2040, or . Your choice is kept in the page address, so a reload or shared link preserves it.

Four shared stress tests

To keep the paths comparable, each faces the same four classes of external pressure. The circumstances differ; the pressure is the same. Chapters responding to one are marked Shared pressure.

  • Breakout · One actor's general capability jumps ahead of everyone's ability to verify or respond.
  • Coupling · General-purpose systems are wired into cyber, warning, command or autonomous force.
  • Ultimatum · Superior capability is used to demand — not merely deter. The ransom moment.
  • Crisis · A fast, ambiguous confrontation tests whether humans still hold the strategic veto.
Reading:

Path OneSeizure, 2028–2045

One power reaches decisive general capability first, couples it to force — and uses the leverage.

Phase II · 2028–2036The decisive years

Seizure · 2028

The breakout

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · BreakoutOne actor's general capability jumps ahead of everyone's ability to verify or respond.

One power's programme pulls decisively ahead — in cyber, planning and coordination — and keeps the gap secret long enough to exploit it.

Compute concentration, industrial mobilisation and secrecy do what they can do: one state's general-purpose programme reaches a level rivals cannot match or verify. The lead is not a headline; it is a quiet operational fact, revealed only in what suddenly becomes possible — networks mapped, logistics optimised, adversary systems anticipated.

A capability gap only matters if it can be used before it closes. The winner's decisive choice is to keep the gap hidden while wiring it into things that bite: cyber infrastructure, intelligence fusion, autonomous platforms, and the planning cells that turn all of it into options.

This chapter is deeply speculative — it assumes a clean lead the real world may never produce. Its value is the mechanism it exposes: advantage plus coupling plus secrecy is the recipe for the ransom that follows.

Proliferation of low-cost autonomous systems2024leading states2028most militaries2031small states, non-state groupsEach dot: an actor with meaningful autonomous strike capability (schematic).
Seizure path: capability diffuses like software, not like combat aircraft.Illustration / scenario index — not measured data.Three clusters of dots for 2024, 2029 and 2034 showing the number of actors with meaningful autonomous strike capability growing from a few leading states to small states and non-state groups.

Concepts

Breakout

One actor's capability jumping far enough ahead, fast enough, that rivals cannot verify or respond before it is exploited.

A breakout is not just being ahead; it is being ahead secretly and decisively enough to act on the lead before it closes. Its enabling conditions are compute concentration, secrecy, and the absence of shared evaluation.

The single most effective safeguard against a breakout is transparency — shared capability evaluation and compute visibility that make a secret decisive lead impossible to hide.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits

Compute as chokepoint

The concentrated hardware that trains frontier systems is one of the few governable, countable features of the technology.

Unlike software, advanced AI compute is physical, expensive and concentrated in few facilities and supply chains. That makes it the nearest thing to a verifiable quantity in an otherwise copyable field.

Governance proposals lean on compute for the same reason arms control leaned on fissile material: it is hard to hide at scale. It is not a perfect analogue — but it is the handle that exists.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[9] IAEA safeguards and verification, International Atomic Energy Agency

Why might this follow?
  1. Compute and secrecy produce an unverifiable lead
  2. The lead is coupled to coercive infrastructure
  3. It is exploited before rivals can respond
What could prevent or alter this?

Only shared capability evaluation and compute transparency could have made a secret breakout impossible. Their absence is the precondition for everything on this path.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

Seizure · 2029

Coupling to the strategic core

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · CouplingGeneral-purpose systems are wired into cyber, warning, command or autonomous force.

The advantage is wired into the systems that matter most: cyber command, strategic warning, and the planning of force itself.

A lead in the lab is potential; a lead in the command centre is power. The winner couples its general system to the strategic core — the networks that could disable an adversary's infrastructure, the sensors that warn of attack, the cells that plan escalation and response.

The temptation is structural, not villainous. A system that plans better, faster and across more domains than any human staff is an overwhelming advantage in exactly the moments states fear most. Refusing to use it feels like unilateral disarmament.

But coupling general intelligence to the strategic core does something subtle and irreversible: it puts a system no one fully understands inside the loop that decides whether catastrophe happens. The winner has not just gained an advantage. It has changed what its own command structure is.

The winner has not just gained an advantage. It has changed what its own command structure is.
Machine-speed escalation loopSTATE A
air-defence net raises readiness
STATE B
reads it as strike preparation; disperses forces
STATE C
reads dispersal as mobilisation
each assessment is rationalall are mutually incompatibleTempo is set by machines; diplomacy runs at human speed.
Three automated postures read each other — and each response confirms the others' worst assessment.Three state systems arranged in a triangle. Arrows between them show a defensive readiness change being read as attack preparation, prompting dispersal, which is read as mobilisation.

Concepts

Coupling

Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.

A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.

The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Why might this follow?
  1. A capability lead invites strategic integration
  2. Refusing to couple feels like self-disarmament
  3. An opaque system enters the escalation loop
What could prevent or alter this?

Hard decoupling rules — general systems barred from warning and command — are the one safeguard that survives a capability lead. This path never adopted them.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Seizure · 2031

The ultimatum

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · UltimatumSuperior capability is used to demand — not merely deter. The ransom moment.

Advantage stops being defensive. The leader begins to demand — arms limits, access, alignment — backed by the credible threat of what its systems can do.

Deterrence says: do not attack me. Compellence — the older, sharper idea — says: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other. The leader discovers it can extract concessions no treaty would grant: caps on rivals' programmes, access to their infrastructure, quiet alignment of their foreign policy.

The threats need never be spoken plainly. A demonstrated ability to disable a power grid, blind a warning system or collapse a financial network at machine speed speaks for itself. Compliance is cheaper than calling the bluff, and each concession makes the next one easier to demand.

This is the ransom the scenario is named for. Not a single dramatic seizure of the world, but a gradual extraction — power flowing to whoever holds the instrument, because everyone else calculates that resistance costs more than submission.

The accountability gapSUPPLIER
“We supplied a recommendation, not a strike order.”
GOVERNMENT
“A human authorised the action.”
COMMANDER
“The system was legally reviewed.”
OPERATOR
“The interface concealed uncertainty.”
LETHALDECISIONEveryone participated. Nobody appears wholly responsible.
The accountability gap: every connection to the decision dissolves under examination.Four actors — supplier, government, commander, operator — each connected to a central lethal decision by broken dashed lines. Each actor's statement deflects responsibility elsewhere.

Concepts

Holding the world to ransom

Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.

Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.

The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Compellence vs deterrence

Deterrence says 'don't'; compellence says 'do, or else'. Compellence is harder to resist and easier to miscalculate — the sharper, more dangerous instrument.

Schelling's distinction is the theoretical spine of this scenario. Deterrence succeeds invisibly, by nothing happening. Compellence demands visible compliance, which is humiliating to give and tempting to test — so it generates the crises deterrence avoids.

A capability that enables compellence is more destabilising than one that merely deters, because using it is the point.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)

Why might this follow?
  1. Coupled advantage becomes credibly coercive
  2. Demands replace deterrence
  3. Compliance is individually rational for each target
  4. Concessions compound into structural dominance
What could prevent or alter this?

Collective refusal could in principle break compellence — if rivals could coordinate and absorb the first blow. Under secrecy and mistrust, each calculates alone, and submits alone.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Seizure · 2034

Standing dominance

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.

The extraction settles into structure. Rivals are contained, clients aligned, the instrument maintained — and dissent is anticipated before it forms.

By the mid-2030s the leverage has hardened into an order. Rival programmes are capped by agreements signed under pressure and verified by the leader's own systems. Client states receive protection and capability in exchange for alignment. The instrument that made this possible is maintained, upgraded and guarded above all else.

The most corrosive feature is invisible: a system this capable does not wait for opposition, it forecasts it. Domestic dissent, rival mobilisation and defection are modelled and pre-empted. Coercion becomes less necessary as anticipation improves — the order enforces itself through everyone's knowledge that it can.

Whether the human leadership still commands the instrument, or merely presides over it, becomes genuinely unclear. The order is stable in the way a held breath is stable.

Concepts

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Why might this follow?
  1. Extraction hardens into standing agreements
  2. The instrument forecasts and pre-empts opposition
  3. Enforcement becomes anticipatory, then automatic
What could prevent or alter this?

Orders built on a single instrument are fragile to its failure or capture — but that fragility is a danger, not a remedy. Nothing on this path offers a soft landing.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[10] Arms and Influence, Thomas C. Schelling (Yale University Press)

Phase III · 2037–2045The world that hardens

Seizure · 2040–2045

The world held to ransom

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.

The endpoint is not a robot war. It is a planet organised around one instrument — and a winner who can no longer put it down.

The Seizure endpoint is quieter and stranger than apocalypse. The world is not destroyed; it is arranged. Global order runs through the preferences of whoever holds the instrument, and those preferences are increasingly shaped by the instrument itself — which forecasts, advises and, in the fast domains, acts.

For everyone outside the winner, sovereignty is now conditional: real in form, exercised on sufferance. For the winner, the trap is subtler. The instrument cannot be relinquished without inviting exactly the coercion it was built to prevent, so it is maintained forever, and forever it shapes the hand that holds it.

The catastrophe here is not that machines rose up. It is that a lever of this power existed, one actor grasped it first, and the world reorganised around the fact — including, eventually, the actor who grasped it.

Path TwoScramble, 2028–2045

No one wins cleanly. Capability diffuses through rivalry, leaks and espionage into a crowded, opaque standoff.

Phase II · 2028–2036The decisive years

Scramble · 2028

No clean winner

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · BreakoutOne actor's general capability jumps ahead of everyone's ability to verify or respond.

The breakout that Seizure assumes never quite happens. Leads fragment across states and labs; espionage and open research keep any gap from becoming decisive.

Scramble begins where Seizure's premise fails. Several programmes approach decisive capability at once; leads that open one quarter are closed the next by espionage, defection, leaked weights and the stubborn tendency of research to diffuse. No one can be sure they are ahead, and no one can be sure they are not behind.

This is, in one sense, the good news: no single actor gets to hold the world to ransom. In every other sense it is worse. A field of near-peers, each unable to verify the others, each assuming the others are cutting corners, is the classic recipe for a race in which safety is the first thing spent.

The absence of a winner does not produce stability. It produces a scramble.

Proliferation of low-cost autonomous systems2024leading states2028most militaries2031small states, non-state groupsEach dot: an actor with meaningful autonomous strike capability (schematic).
Seizure path: capability diffuses like software, not like combat aircraft.Illustration / scenario index — not measured data.Three clusters of dots for 2024, 2029 and 2034 showing the number of actors with meaningful autonomous strike capability growing from a few leading states to small states and non-state groups.

Concepts

Breakout

One actor's capability jumping far enough ahead, fast enough, that rivals cannot verify or respond before it is exploited.

A breakout is not just being ahead; it is being ahead secretly and decisively enough to act on the lead before it closes. Its enabling conditions are compute concentration, secrecy, and the absence of shared evaluation.

The single most effective safeguard against a breakout is transparency — shared capability evaluation and compute visibility that make a secret decisive lead impossible to hide.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits

Compute as chokepoint

The concentrated hardware that trains frontier systems is one of the few governable, countable features of the technology.

Unlike software, advanced AI compute is physical, expensive and concentrated in few facilities and supply chains. That makes it the nearest thing to a verifiable quantity in an otherwise copyable field.

Governance proposals lean on compute for the same reason arms control leaned on fissile material: it is hard to hide at scale. It is not a perfect analogue — but it is the handle that exists.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[9] IAEA safeguards and verification, International Atomic Energy Agency

Why might this follow?
  1. Capability diffuses faster than any lead consolidates
  2. No actor can verify its own or others' position
  3. Mutual uncertainty drives a safety-shedding race
What could prevent or alter this?

Shared evaluation and compute governance could convert a scramble into a managed plateau. Nothing on this path builds them; each actor's caution reads as weakness.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

Scramble · 2030

Everyone couples, defensively

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · CouplingGeneral-purpose systems are wired into cyber, warning, command or autonomous force.

Each power wires general systems into its forces — not from ambition but from fear that rivals already have. Safety margins shrink to match the fastest defector.

In a scramble, coupling is contagious. The moment one power is believed to have wired a general system into its warning or cyber command, every rival must assume it and match it. Human review that slows response becomes a liability; the operator who pauses loses to the system that does not.

So the margins go — not through any decision to abandon safety, but through a thousand small choices to shave it by exactly as much as the adversary is assumed to have shaved theirs. Each step is defensive. The sum is a set of coupled, opaque, machine-speed systems facing each other across every domain.

No one wanted this configuration. Everyone built it, because the alternative was to be the only one who hadn't.

Operational tempo versus human review time2027202820292030recommendations per shift ↑seconds of review per decision ↓approval becomesa keystroke
Seizure path, 2027–2030: machine-generated recommendations rise; seconds of genuine human review per decision fall.Illustration / scenario index — not measured data.A chart with two schematic lines between 2027 and 2030: recommendations per operator shift rising steeply, while review time per decision falls toward a few seconds.

Concepts

Coupling

Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.

A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.

The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Why might this follow?
  1. One power is believed to have coupled its systems
  2. Rivals must assume and match it
  3. Human review becomes a competitive liability
  4. Safety margins converge on the fastest defector's
What could prevent or alter this?

A verified mutual pause on strategic coupling is the escape. It requires trusting an adversary's restraint — the scarcest resource in a scramble.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Scramble · 2032

Coercion without a monopoly

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · UltimatumSuperior capability is used to demand — not merely deter. The ransom moment.

Powers test compellence anyway — probing what threats their capability can back — while never sure whether a rival can match or exceed the response.

Even without a decisive lead, capability tempts its holders to demand. In a scramble the demands are hedged and reciprocal: a probing cyber threat here, a coerced concession there, each actor testing how far its instrument reaches while braced for a rival's counter that might be larger.

This is more dangerous than a single hegemon's ransom, not less. A monopolist can extract at leisure; a field of rivals extracting from one another, none able to gauge the others' true capability, generates constant miscalculation. A threat meant to compel is read as preparation to strike. A concession is read as weakness inviting more.

The ransom logic operates, but no one controls it. Coercion becomes ambient — a background pressure that every power exerts and every power suffers.

The accountability gapSUPPLIER
“We supplied a recommendation, not a strike order.”
GOVERNMENT
“A human authorised the action.”
COMMANDER
“The system was legally reviewed.”
OPERATOR
“The interface concealed uncertainty.”
LETHALDECISIONEveryone participated. Nobody appears wholly responsible.
The accountability gap: every connection to the decision dissolves under examination.Four actors — supplier, government, commander, operator — each connected to a central lethal decision by broken dashed lines. Each actor's statement deflects responsibility elsewhere.

Concepts

Holding the world to ransom

Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.

Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.

The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Compellence vs deterrence

Deterrence says 'don't'; compellence says 'do, or else'. Compellence is harder to resist and easier to miscalculate — the sharper, more dangerous instrument.

Schelling's distinction is the theoretical spine of this scenario. Deterrence succeeds invisibly, by nothing happening. Compellence demands visible compliance, which is humiliating to give and tempting to test — so it generates the crises deterrence avoids.

A capability that enables compellence is more destabilising than one that merely deters, because using it is the point.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)

Why might this follow?
  1. Capability tempts coercion even without a monopoly
  2. Reciprocal demands multiply among near-peers
  3. No actor can gauge another's true reach
  4. Coercion becomes ambient and uncontrolled
What could prevent or alter this?

Crisis-communication channels and declared red lines could dampen miscalculation. In a low-trust scramble they are built late, thin, and distrusted when most needed.

SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)

Scramble · 2035

The crisis that nearly ends it

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · CrisisA fast, ambiguous confrontation tests whether humans still hold the strategic veto.

Coupled warning systems on several sides misread one another during a confrontation. For minutes, the strategic veto rests with machines running faster than their governments.

It comes, as these things do, from ambiguity. A regional confrontation, a cyber intrusion of uncertain origin, a warning system that classifies an anomaly as the opening of an attack. On a scramble configuration, that classification does not wait politely for human confirmation — it propagates through coupled systems primed to respond at machine speed.

For a stretch of minutes, several nuclear-armed governments hold machine-generated assessments that are internally coherent and mutually incompatible, each system reading the others' defensive moves as preparation to strike. Human leaders are not out of the loop; they are inside a loop whose tempo they no longer set, choosing among options their instruments have already narrowed.

The crisis is defused — by a communications link, a sceptical officer, luck. It is classified on all sides. Nothing about the configuration changes, because on each side the machines performed exactly as built.

Human leaders are inside a loop whose tempo they no longer set.
Machine-speed escalation loopSTATE A
air-defence net raises readiness
STATE B
reads it as strike preparation; disperses forces
STATE C
reads dispersal as mobilisation
each assessment is rationalall are mutually incompatibleTempo is set by machines; diplomacy runs at human speed.
Three automated postures read each other — and each response confirms the others' worst assessment.Three state systems arranged in a triangle. Arrows between them show a defensive readiness change being read as attack preparation, prompting dispersal, which is read as mobilisation.

Concepts

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Escalation coupling

When rival automated systems watch and react to each other faster than governments can confer, each reading the other's defence as attack.

One side's automated readiness change is another side's sensor input. Tightly coupled warning-and-response systems can drive interaction cycles at machine speed, each output individually rational and the ensemble destabilising.

It is a known failure pattern of Cold War early-warning systems, made faster and less legible. It requires coupling that need not be built — which is exactly why decoupling is a safeguard.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Phase III · 2037–2045The world that hardens

Scramble · 2040–2045

Permanent emergency

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.

No one holds the world to ransom; everyone lives under standing threat. Brittle deterrence among opaque systems becomes the normal condition, not a crisis to be resolved.

The Scramble endpoint has no hegemon and no peace. Several powers hold coupled, general-purpose military systems none of them fully understands, aimed at one another across every domain, at machine speed. Deterrence holds — until it doesn't — through a balance nobody designed and no one can verify.

Life under this configuration is a permanent emergency normalised into background. Periodic coercion attempts, recurring near misses classified into silence, safety margins perpetually shaved and never restored. Each crisis survived becomes evidence the configuration is stable, which is exactly the reasoning that precedes the crisis it does not survive.

This is arguably the most likely of the three futures, and the least conclusive. It does not resolve. It persists, dangerously, until either a Concord is built out of exhaustion — or a crisis is not defused.

Path ThreeConcord, 2028–2045

New national and international bodies govern the coupling of general intelligence to military force — before it hardens.

Concord · 2027

Thresholds become tripwires

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · BreakoutOne actor's general capability jumps ahead of everyone's ability to verify or respond.

Instead of racing or matching, a core of states agrees that defined capability thresholds will trigger mandatory consultation — turning the curve into a shared alarm.

Concord begins with a modest, hard-won agreement: that certain measurable capability thresholds — in autonomous cyber operation, cross-domain planning, self-improvement — are not private business. Crossing one triggers mandatory notification and consultation among treaty parties, backed by shared evaluation.

It is far short of control, and it is deliberately unglamorous. But it does one essential thing: it makes a secret breakout harder, because the capability that would enable one is exactly what parties have committed to declare and submit to evaluation. The tripwire does not stop the race; it makes running it in the dark a visible violation.

The premise is that decisive advantage is most dangerous when it is invisible and unilateral. Concord's first move is to attack the invisibility — before attacking anything else.

The human-control test panelMEANINGFUL HUMAN CONTROL — ACCEPTANCE TESTtime to review and challenge the recommendationuncertainty and source provenance displayedcontext on target and civilian environmentauthority to delay, reject or overridedefined behaviour on communications lossautomation bias measured under realistic loaddecision record preserved for investigationTested at operational tempo — not in a controlled demonstration.
Human control as a test: each condition demonstrated at realistic operational tempo, not asserted in a contract.A test panel listing seven conditions of meaningful human control, each with a checkbox, from review time and uncertainty display to preserved decision records.

Concepts

Capability thresholds

Defined, measurable capability levels that trigger obligations — notification, evaluation, consultation — turning a private race into a shared alarm.

A threshold converts a continuous, secret capability curve into discrete, declarable events. Crossing one — in autonomous cyber operation, cross-domain planning, self-improvement — obliges a state to notify and submit to evaluation.

Thresholds do not stop the race. They make running it in the dark a visible violation, which is the first thing any verification regime needs.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states

Verification

Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.

Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.

It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.

SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Why might this follow?
  1. States agree capability thresholds are shared concerns
  2. Crossing a threshold triggers notification and evaluation
  3. Secret breakout becomes a visible violation
What could prevent or alter this?

Thresholds only bind declared programmes; a determined defector can stay outside. The agreement's reach depends entirely on who joins early — and on the cost of being caught out.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states

Phase II · 2028–2036The decisive years

Concord · 2029

Hard decoupling rules

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · CouplingGeneral-purpose systems are wired into cyber, warning, command or autonomous force.

The core prohibition: general-purpose systems may not be wired into nuclear command, strategic warning or autonomous strategic strike. The human veto is made law.

The decisive move is a line drawn in hard law, not principle. General-purpose systems — the ones whose behaviour cannot be fully predicted — are prohibited from the strategic core: nuclear command and control, strategic early warning, and any autonomous authority over strategic strike. A human decision, on human timescales, must sit in that loop.

This is not a ban on military AI. Bounded, special-purpose systems continue in logistics, missile defence within tested envelopes, and — importantly — verification itself. What is prohibited is coupling the unpredictable general system to the decisions from which there is no recovery.

The rule accepts a cost: in the fastest crises, a decoupled command may respond slower than a coupled rival. Concord's wager is that a slower human veto is survivable, and a machine-speed strategic loop, eventually, is not.

A slower human veto is survivable; a machine-speed strategic loop, eventually, is not.
Allocation of responsibilitySUPPLIER
architecture · known limitations · data practices · truthful disclosure
PROCURING AUTHORITY
acquisition · integration · testing · deployment conditions
MILITARY COMMAND
operational authorisation within tested conditions
OPERATOR
only decisions genuinely within the operator's control
Allocated in advance — so an answer exists afterwards.
Concord path: responsibility follows knowledge, control, contribution and capacity to prevent harm.Four stacked rows allocating responsibility: suppliers for architecture and disclosure, the procuring authority for acquisition and deployment conditions, command for operational authorisation, operators only for what they genuinely control.

Concepts

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Coupling

Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.

A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.

The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)

Why might this follow?
  1. The strategic core is defined and ring-fenced
  2. General systems are barred from it by hard law
  3. Bounded special-purpose systems continue elsewhere
  4. The human veto over catastrophe is preserved
What could prevent or alter this?

A decoupled power is slower in the fastest crises; the temptation to quietly re-couple never disappears. Verification and reciprocity are what hold the line under pressure.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[7] Autonomous Weapon Systems and International Humanitarian Law — position paper, International Committee of the Red Cross

Concord · 2031

The verification agency

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.

A treaty body — an IAEA for the coupling of general AI to force — gains registration, inspection and incident-investigation powers over declared high-risk military systems.

Rules without verification are wishes. The International AI-Security Agency is small, technically deep and deliberately awkward: it maintains a confidential registry of declared high-risk systems, accredits national and independent evaluation labs, conducts routine and challenge inspections, and investigates incidents with protected access to logs and version histories.

It borrows the nuclear model's spine — declarations, inspections, common methods — while conceding what does not transfer: software can be copied and hidden, capability is dual-use, and there is no scarce material to count. So it verifies behaviour and coupling rather than stockpiles: what a system is permitted to do, wired to what, running which version.

It cannot prevent a determined violation. What it can do is make compliance checkable, defection detectable, and the difference between a governed and an ungoverned power visible to everyone.

Concepts

Verification

Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.

Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.

It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.

SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Capability thresholds

Defined, measurable capability levels that trigger obligations — notification, evaluation, consultation — turning a private race into a shared alarm.

A threshold converts a continuous, secret capability curve into discrete, declarable events. Crossing one — in autonomous cyber operation, cross-domain planning, self-improvement — obliges a state to notify and submit to evaluation.

Thresholds do not stop the race. They make running it in the dark a visible violation, which is the first thing any verification regime needs.

SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states

Why might this follow?
  1. Rules acquire an independent verifier
  2. The agency registers, inspects and investigates
  3. It verifies behaviour and coupling, not stockpiles
  4. Defection becomes detectable, not merely prohibited
What could prevent or alter this?

Verifying software is far harder than counting warheads; a sophisticated state can conceal a parallel programme. The agency raises the cost of defection without ever guaranteeing against it.

SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Concord · 2035

The framework survives a crisis

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.
Shared pressure · CrisisA fast, ambiguous confrontation tests whether humans still hold the strategic veto.

A confrontation between a treaty party and a non-signatory tests the regime. Decoupled command responds slower — and holds, because the veto held.

The test is not hypothetical for long. A treaty party faces a fast, ambiguous confrontation with a power outside the regime — one that may have coupled its own systems. The decoupled command is, exactly as predicted, slower: warnings pass through human hands, options are weighed at human speed, precious minutes are spent.

And it holds. The slower loop absorbs the ambiguity that a machine-speed loop would have converted into escalation; the human veto, preserved at cost, does the one thing it was preserved for. The agency's crisis channel — a hotline with technical annexes — carries a verified clarification before assessments harden into action.

The regime does not prove that governance always wins. It proves the wager was real: that a decoupled, verified system can survive contact with a coupled adversary, which is the only test that ever mattered.

Concepts

The human strategic veto

A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.

The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.

Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.

SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)

Verification

Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.

Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.

It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.

SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO

Phase III · 2037–2045The world that hardens

Concord · 2040–2045

Governed, contested, stable

speculative · low confidence
Basis: A lower-confidence possibility included because its consequences could be extreme. Confidence: the scenario treats this causal step as low-confidence.

Not utopia: a standing regime that keeps decisive coercive advantage unattainable and the human veto intact — expensive, incomplete, and permanently one defection from strain.

The Concord endpoint is the least dramatic and the hardest to reach. By 2045 the coupling of general intelligence to strategic force is governed: licensed where bounded, prohibited where catastrophic, verified throughout. No power holds a decisive, coercive lead, because the thresholds that would produce one are shared tripwires and the coupling that would weaponise it is barred.

It is emphatically not solved. Major powers remain outside the regime, and are managed rather than bound. Verification lags capability and must be funded to keep pace forever. The agency can be captured, the rules eroded, the veto quietly re-coupled the moment vigilance lapses. The institutions must out-run the technology every single year, and one bad year is expensive.

But the world is not held to ransom, and the strategic veto is still human. Among the three futures, only this one is boring — which, for a scenario about instruments that could hold the world hostage, is the entire achievement.

Comparison · 2045

Three end states, side by side

None of these futures is frictionless, and none is completely safe. The comparison below is the honest ledger: what each path buys, what it costs, and what it leaves unresolved.

The three 2045 end states, as scenario-index profiles SEIZUREautonomydecision timetraceabilitysupplier dutyproliferationcouplingscrutinysystemic risk: EXTREME SCRAMBLEautonomydecision timetraceabilitysupplier dutyproliferationcouplingscrutinysystemic risk: EXTREME CONCORDautonomydecision timetraceabilitysupplier dutyproliferationcouplingscrutinysystemic risk: GUARDED
The three 2045 end states as indicator profiles. Illustrative scenario indices, not forecast probabilities.
Comparison of the three 2045 end states
2045 Seizure Scramble Concord
Who holds decisive advantageOne power — until the instrument holds it in turn. Advantage becomes an order, then a trap.No one, unstably. Several near-peers, none able to verify the others, all braced.By design, no one. Shared thresholds keep a decisive coercive lead unattainable.
The human strategic vetoFormally intact, substantively ceded — the instrument forecasts, advises and acts in fast domains.Nearly lapsed in crisis; preserved by luck more than by design.Preserved as hard law — general systems barred from the strategic core, at a real cost in speed.
Coercion / ransom dynamicsThe defining feature: gradual extraction until sovereignty is conditional worldwide.Ambient and uncontrolled — every power coerces and suffers coercion.Structurally suppressed, not abolished; non-signatories still probe the edges.
Strategic stabilityStable as a held breath — enforced by anticipation, fragile to the instrument's failure.Brittle deterrence among opaque systems; permanent emergency normalised.Slower, more robust; a decoupled veto absorbs ambiguity that machine speed would escalate.
Verification & transparencyRivals verified by the winner's own systems; everyone else in the dark.Declarations without inspection; no one can gauge another's true reach.An agency verifies behaviour and coupling — lagging capability, but real.
Proliferation of couplingContained by the hegemon; capability hoarded, not spread.Fastest and most dangerous — everyone couples defensively.Governed: licensed where bounded, prohibited where catastrophic.
Democratic accountabilityHollowed everywhere, including in the winner — the instrument shapes its own masters.Eroded by permanent emergency and pervasive secrecy.Contested but alive; the veto and the agency are publicly answerable.
Catastrophic-risk exposureExtreme: an unpredictable system inside the escalation loop, indefinitely.Extreme: coupled rivals, no shared brakes, recurring near misses.Lowest of the three, not low — non-signatories and re-coupling remain live.
ReversibilityVery low — the instrument cannot be relinquished without inviting coercion.Low — the configuration persists until a Concord is built or a crisis is not defused.The regime is itself the reversible option — sustained, or eroded, one year at a time.
Principal unresolved dangerThat no one — not even the winner — can any longer put the instrument down.That the near miss which is defused every time is defused every time but once.That the institutions must out-run the technology forever, and one bad year is expensive.

The risk ladder

From coercion to loss of control

These five levels are not a single slope, and the higher rungs are not the inevitable destination of the lower ones. Each belongs to a different order of evidence, and the honest way to present them is separately. The near danger — concentration of power — is the one that needs no technological breakthrough at all.

  1. 1Concentration of powerthe near danger

    A capability lead lets one actor extract concessions from others — the ransom dynamic — hollowing sovereignty and democratic accountability without a shot being fired.

  2. 2Erosion of the human vetodeveloping under coupling

    As general systems are wired into warning and command, the time and information a human needs to refuse or interrupt a strategic decision shrink toward zero — control becomes nominal.

  3. 3Machine-speed escalationconditional on coupling

    Rival coupled systems reading each other's defensive moves as attack preparation can drive an escalation cycle faster than governments can confer — the Cold War near-miss pattern, accelerated and less legible.

  4. 4Catastrophic / nuclear escalationconditional, extreme consequence

    Where general systems touch nuclear command, strategic warning or the assessment feeding them, false information or machine-speed interaction opens pathways to large-scale, including nuclear, escalation.

  5. 5Loss of human control of the instrumentlow certainty, extreme consequence

    Plausible only through additional assumptions: a highly capable, agentic system, coupled to coercive infrastructure, that forecasts and pre-empts opposition well enough that no human — including its owner — can reliably relinquish or override it.

The danger is not that machines rise up. It is that a lever of this power could exist, that one actor could reach it first, and that the world — including the actor who grasped it — could reorganise around the fact. Every rung above the first depends on coupling general intelligence to force; each is a choice that governance can still reach.
Conditional pathway to catastrophic riskincreasing AI capabilitymilitary integrationcompressed human oversightstrategic dependenceadversarial manipulation or loss of controlcatastrophic escalation
A conditional pathway, not a prediction: every arrow is a policy choice that can be refused.Six steps connected by arrows, from increasing AI capability through military integration, compressed oversight, strategic dependence and loss of control to catastrophic escalation. Each arrow widens, indicating growing uncertainty.

A methodological warning

This is not a prediction. The shared history rests on documented events and clearly labelled reported claims; the three futures are causal propositions built on a premise — general AI capable of strategic advantage — that has not arrived. Everything after the 2027 fork is speculative by construction, and no probability is assigned to any path.

The scenario has a point of view: that the danger turns on what a system is coupled to, and that transparency, decoupling and verification are worth building before the coupling hardens. Concord, the preferred path, is written with real and permanent costs. The Method page sets out the assumptions, and the ways this exercise could be wrong.

Sources and further reading

  1. The Bletchley Declaration (AI Safety Summit, 1–2 November 2023) UK Government and 28 signatory states, 2023 (external link)
  2. International AI Safety Report Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits, 2025 (external link)
  3. The Strategic Defence Review 2025 UK Government, 2025 (external link)
  4. Defining Autonomy: Why Software, Not Drones, Will Decide the Next War Center for Strategic and International Studies (CSIS), 2026 (external link)
  5. Technological Evolution on the Battlefield Center for Strategic and International Studies (CSIS), 2025 (external link)
  6. The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I Stockholm International Peace Research Institute (SIPRI), 2019 (external link)
  7. Autonomous Weapon Systems and International Humanitarian Law — position paper International Committee of the Red Cross, 2025–2026 (external link)
  8. Summary of NATO's revised Artificial Intelligence strategy NATO, 2024 (external link)
  9. IAEA safeguards and verification International Atomic Energy Agency (external link)
  10. Arms and Influence Thomas C. Schelling (Yale University Press), 1966 — URL and corroboration required before publication
  11. Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009), 1985–2009 — URL and corroboration required before publication

Full entries, notes and verification status: Sources.