When intelligence meets the trigger
One instrument. Three futures. A world that could be held to ransom.
A scenario study of general-purpose AI and military force · 2023–2045
Militaries have already rebuilt themselves around software: sensors, data links, targeting webs and autonomous platforms, waiting for a better brain. General-purpose AI is becoming that brain — a system that can plan, coordinate and decide across domains at machine speed.
The question this scenario asks is not whether AI will be used in war. It is what happens when a general-purpose system capable of strategic advantage is coupled to force — and whether one actor could use that advantage to hold the rest of the world to ransom.
This is not a prediction. It is a structured examination of three futures that branch from the same starting point: Seizure, in which one power wins and abuses the lead; Scramble, in which no one wins and everyone lives under standing threat; and Concord, in which new national and international bodies govern the coupling before it hardens.
Why 2045? The decisive choices arrive in the late 2020s. 2045 shows what happens after capability, infrastructure and institutions fuse into a fact that cannot easily be undone.
A public-interest scenario exercise, not a prediction. One shared timeline (2023–2027) divides in 2027 into three futures, each followed to 2045. Every major entry is labelled by its evidential status, and the assumptions are set out on the Method page so that researchers and policymakers can inspect — and contest — them.
A capability that could hold the world to ransom is hard to reason about in the abstract. Following it through rivalry, secrecy, crisis and institution-building reveals consequences that static analysis misses. A scenario asks a strategy the question a crisis will eventually ask it — on paper, first.
A general-purpose model in a lab is inert. It becomes dangerous when it is coupled — wired into infrastructure that acts:
The governance question is not ‘how smart is the system’ but ‘what is it wired into’. Decoupling — barring general systems from the strategic core — is the one safeguard that survives even a capability lead.
The danger is not that the machine decides to seize the world. It is that a lever this powerful exists, and someone reaches it first.
Every major entry states its basis— one of four labels — plus, where a claim rests on reporting, its corroboration status, and the scenario's causal confidence:
The 2023–2027 shared history is documented or clearly-labelled reported material. Everything after the 2027 fork is projected or speculative by construction — these are three possible futures, not forecasts, and no probability is assigned to any of them. All numerical indicators in the monitor are illustrative scenario indices, not forecast probabilities. Factual claims have a July 2026 evidence cut-off.
Phase I · 2023–2027 — The coupling begins
— Shared history · 2023
Twenty-nine governments sign the Bletchley Declaration, conceding that frontier general-purpose AI could cause 'serious, even catastrophic, harm' — including through misuse and loss of control.
The Bletchley Declaration is not a treaty, and it binds no one. Its significance is admission: assembled at Bletchley Park, rival governments agreed on paper that the most capable general-purpose systems carry catastrophic potential, specifically naming intentional misuse and problems of human control.
What the declaration does not do is decide who governs the meeting of those systems with coercive power. It records a shared fear and defers the hard question — which is the question this scenario is about.
Two things are true at once in 2023. General-purpose models are still tools, not strategic actors. And the states that will most shape their military use have just signed a document saying, in effect, that they are afraid of what they are building.
Rival governments agreed on paper that they are afraid of what they are building — and then deferred the question of who governs it.
Concepts
A system that performs well across many tasks it was not specifically trained for — the 'frontier' models the Bletchley Declaration flagged as potentially catastrophic.
Special-purpose military AI does one thing: classify this image, guide this munition. A general-purpose system plans, reasons, writes code, coordinates and adapts across domains. That breadth is what makes it strategically consequential — and what makes its behaviour hard to predict or bound.
This scenario is about what happens when systems on that frontier become good enough to matter to a war planner, and are wired into force.
SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits
Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.
A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.
The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
The summit process could have moved from declaration to verifiable commitments while capability was still modest. Whether it does is the whole story after 2027.
SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits
— Shared history · 2025
Before general AI is strategically decisive, the wiring is in place: uncrewed systems at scale, machine-speed targeting, software as the locus of lethal decision.
The danger this scenario tracks needs two ingredients. One is general capability — still maturing in 2025. The other is a military already rebuilt around software, and that already exists. The UK Strategic Defence Review commits to uncrewed systems at scale and machine-speed targeting; independent analysis finds the locus of lethal decision moving into integration layers; detection-to-strike cycles run in tens of seconds.
This matters because it means the socket is ready before the plug. When general-purpose systems become good enough to plan, coordinate and decide across domains, they will not meet an analogue military. They will meet sensors, data links, targeting webs and autonomous platforms waiting for a better brain.
The coupling, when it comes, will be an upgrade — not an invention.
Concepts
Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.
A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.
The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
Find, fix, track, target, engage, assess — the sequence AI already assists at every stage, and which a general system could run end to end.
Modern targeting is an integration problem, not a trigger. Each stage — sensing, geolocation, tracking, ranking, guidance, assessment — already takes AI assistance. A sufficiently capable general system could plan and re-plan across all of them at machine speed.
That is the socket a more capable 'brain' plugs into. The wiring exists before the intelligence that would abuse it.
SOURCES [4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)[5] Technological Evolution on the Battlefield, Center for Strategic and International Studies (CSIS)
Governing the socket — what any system may be wired into — is possible before the most capable plug arrives. After it arrives, governance competes with advantage.
SOURCES [3] The Strategic Defence Review 2025, UK Government[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)[5] Technological Evolution on the Battlefield, Center for Strategic and International Studies (CSIS)
— Shared history · 2026
General-purpose systems begin to outperform expert teams at planning, cyber operations and coordination in tests. Not decisive — but no longer obviously bounded.
By 2026 the question stops being whether general models are useful and becomes how far the curve runs. In evaluations, the strongest systems match or beat expert teams at multi-step planning, vulnerability discovery and the coordination of many simultaneous tasks — the exact competencies that, at scale, translate into strategic advantage.
Nothing here is a strategic actor yet. The systems still need operators, infrastructure and permission. But three capabilities are converging that a military planner cannot ignore: the ability to find and exploit software weaknesses faster than defenders patch; to plan and re-plan operations across domains at machine speed; and to run all of it at a cost that favours whoever has the most compute.
This is the threshold at which governance and advantage begin to compete for the same decision.
Concepts
A system that performs well across many tasks it was not specifically trained for — the 'frontier' models the Bletchley Declaration flagged as potentially catastrophic.
Special-purpose military AI does one thing: classify this image, guide this munition. A general-purpose system plans, reasons, writes code, coordinates and adapts across domains. That breadth is what makes it strategically consequential — and what makes its behaviour hard to predict or bound.
This scenario is about what happens when systems on that frontier become good enough to matter to a war planner, and are wired into force.
SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits
A lead large enough to change outcomes between states — in this scenario, driven by cyber, cross-domain planning and coordination at compute-limited cost.
Not every capability gain is strategic. What matters here is the cluster that compounds with scale: finding software weaknesses faster than defenders patch, planning operations across domains, and coordinating many actions at once, all at a cost set by who has the most compute.
A decisive lead in these is the precondition for coercion. Keeping it shared and visible is the precondition for governance.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
Independent capability evaluation, if states trusted it, could keep this threshold visible and shared. Without it, each power sees only its own curve — and assumes the worst about others'.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
— Shared history · 2027
The curve keeps rising. Three responses are on the table — win it, match it, or govern it — and for a brief window all three are still possible.
In 2027 the compute, the capability and the military substrate line up, and the world faces a choice it will not get to make twice. The strongest programmes are close enough to decisive advantage that racing looks rational; diffuse enough that no one is sure they can win; and dangerous enough that governing them is finally, visibly urgent.
Three logics contend. Seize it: reach decisive capability first and use the lead before rivals close it. Scramble: assume no one wins, and match every move defensively. Concord: accept that no actor should hold this lever alone, and build the institutions to govern the coupling before it hardens.
The choice is not purely anyone's to make — it emerges from thousands of decisions by states, labs and militaries. But its centre of gravity is set now, in the narrow window before capability and infrastructure fuse into a fact.
Concepts
A lead large enough to change outcomes between states — in this scenario, driven by cyber, cross-domain planning and coordination at compute-limited cost.
Not every capability gain is strategic. What matters here is the cluster that compounds with scale: finding software weaknesses faster than defenders patch, planning operations across domains, and coordinating many actions at once, all at a cost set by who has the most compute.
A decisive lead in these is the precondition for coercion. Keeping it shared and visible is the precondition for governance.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.
Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.
The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
SOURCES [1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits
The governance fork
When general intelligence can be coupled to force, who decides how — and does anyone hold the lever alone?
“Nobody should hold that lever alone. Build the governing institutions before the coupling hardens.”
“Advantage will decide, as it always has.”
“Yes — and a lead that big will be used.”
“No — the lead leaks, fragments and multiplies.”
Reading all three paths in sequence. Select a box to follow one.
Path One: Seizure. Path Two: Scramble. Path Three: Concord. Selecting a path filters the timeline below to that future.The three paths in detail
▲ Path One
Seizure
“One power reaches decisive general capability first, couples it to force — and uses the leverage.”
Compute concentration, secrecy and industrial mobilisation produce a genuine capability gap. The gap is coupled to coercive infrastructure before anyone else can respond, and the first demands follow — politely at first.
■ Path Two
Scramble
“No one wins cleanly. Capability diffuses through rivalry, leaks and espionage into a crowded, opaque standoff.”
The Seizure premise fails — the lead fragments across states and labs — but nothing replaces it. Each actor couples general systems to its forces defensively, creating exactly the machine-speed instability everyone feared.
● Path Three
Concord
“New national and international bodies govern the coupling of general intelligence to military force — before it hardens.”
Built in stages from 2027: capability thresholds trigger treaty consultations; a national licensing authority and an international verification agency govern military applications of general-purpose AI; decoupling rules are hard law, not principles.
Follow one path to 2040, or . Your choice is kept in the page address, so a reload or shared link preserves it.
Four shared stress tests
To keep the paths comparable, each faces the same four classes of external pressure. The circumstances differ; the pressure is the same. Chapters responding to one are marked Shared pressure.
▲ Path One — Seizure, 2028–2045
One power reaches decisive general capability first, couples it to force — and uses the leverage.
Phase II · 2028–2036 — The decisive years
▲ Seizure · 2028
One power's programme pulls decisively ahead — in cyber, planning and coordination — and keeps the gap secret long enough to exploit it.
Compute concentration, industrial mobilisation and secrecy do what they can do: one state's general-purpose programme reaches a level rivals cannot match or verify. The lead is not a headline; it is a quiet operational fact, revealed only in what suddenly becomes possible — networks mapped, logistics optimised, adversary systems anticipated.
A capability gap only matters if it can be used before it closes. The winner's decisive choice is to keep the gap hidden while wiring it into things that bite: cyber infrastructure, intelligence fusion, autonomous platforms, and the planning cells that turn all of it into options.
This chapter is deeply speculative — it assumes a clean lead the real world may never produce. Its value is the mechanism it exposes: advantage plus coupling plus secrecy is the recipe for the ransom that follows.
Concepts
One actor's capability jumping far enough ahead, fast enough, that rivals cannot verify or respond before it is exploited.
A breakout is not just being ahead; it is being ahead secretly and decisively enough to act on the lead before it closes. Its enabling conditions are compute concentration, secrecy, and the absence of shared evaluation.
The single most effective safeguard against a breakout is transparency — shared capability evaluation and compute visibility that make a secret decisive lead impossible to hide.
The concentrated hardware that trains frontier systems is one of the few governable, countable features of the technology.
Unlike software, advanced AI compute is physical, expensive and concentrated in few facilities and supply chains. That makes it the nearest thing to a verifiable quantity in an otherwise copyable field.
Governance proposals lean on compute for the same reason arms control leaned on fissile material: it is hard to hide at scale. It is not a perfect analogue — but it is the handle that exists.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[9] IAEA safeguards and verification, International Atomic Energy Agency
Only shared capability evaluation and compute transparency could have made a secret breakout impossible. Their absence is the precondition for everything on this path.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
▲ Seizure · 2029
The advantage is wired into the systems that matter most: cyber command, strategic warning, and the planning of force itself.
A lead in the lab is potential; a lead in the command centre is power. The winner couples its general system to the strategic core — the networks that could disable an adversary's infrastructure, the sensors that warn of attack, the cells that plan escalation and response.
The temptation is structural, not villainous. A system that plans better, faster and across more domains than any human staff is an overwhelming advantage in exactly the moments states fear most. Refusing to use it feels like unilateral disarmament.
But coupling general intelligence to the strategic core does something subtle and irreversible: it puts a system no one fully understands inside the loop that decides whether catastrophe happens. The winner has not just gained an advantage. It has changed what its own command structure is.
The winner has not just gained an advantage. It has changed what its own command structure is.
Concepts
Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.
A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.
The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Hard decoupling rules — general systems barred from warning and command — are the one safeguard that survives a capability lead. This path never adopted them.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
▲ Seizure · 2031
Advantage stops being defensive. The leader begins to demand — arms limits, access, alignment — backed by the credible threat of what its systems can do.
Deterrence says: do not attack me. Compellence — the older, sharper idea — says: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other. The leader discovers it can extract concessions no treaty would grant: caps on rivals' programmes, access to their infrastructure, quiet alignment of their foreign policy.
The threats need never be spoken plainly. A demonstrated ability to disable a power grid, blind a warning system or collapse a financial network at machine speed speaks for itself. Compliance is cheaper than calling the bluff, and each concession makes the next one easier to demand.
This is the ransom the scenario is named for. Not a single dramatic seizure of the world, but a gradual extraction — power flowing to whoever holds the instrument, because everyone else calculates that resistance costs more than submission.
Concepts
Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.
Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.
The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
Deterrence says 'don't'; compellence says 'do, or else'. Compellence is harder to resist and easier to miscalculate — the sharper, more dangerous instrument.
Schelling's distinction is the theoretical spine of this scenario. Deterrence succeeds invisibly, by nothing happening. Compellence demands visible compliance, which is humiliating to give and tempting to test — so it generates the crises deterrence avoids.
A capability that enables compellence is more destabilising than one that merely deters, because using it is the point.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)
Collective refusal could in principle break compellence — if rivals could coordinate and absorb the first blow. Under secrecy and mistrust, each calculates alone, and submits alone.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
▲ Seizure · 2034
The extraction settles into structure. Rivals are contained, clients aligned, the instrument maintained — and dissent is anticipated before it forms.
By the mid-2030s the leverage has hardened into an order. Rival programmes are capped by agreements signed under pressure and verified by the leader's own systems. Client states receive protection and capability in exchange for alignment. The instrument that made this possible is maintained, upgraded and guarded above all else.
The most corrosive feature is invisible: a system this capable does not wait for opposition, it forecasts it. Domestic dissent, rival mobilisation and defection are modelled and pre-empted. Coercion becomes less necessary as anticipation improves — the order enforces itself through everyone's knowledge that it can.
Whether the human leadership still commands the instrument, or merely presides over it, becomes genuinely unclear. The order is stable in the way a held breath is stable.
Concepts
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Orders built on a single instrument are fragile to its failure or capture — but that fragility is a danger, not a remedy. Nothing on this path offers a soft landing.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[10] Arms and Influence, Thomas C. Schelling (Yale University Press)
Phase III · 2037–2045 — The world that hardens
▲ Seizure · 2040–2045
The endpoint is not a robot war. It is a planet organised around one instrument — and a winner who can no longer put it down.
The Seizure endpoint is quieter and stranger than apocalypse. The world is not destroyed; it is arranged. Global order runs through the preferences of whoever holds the instrument, and those preferences are increasingly shaped by the instrument itself — which forecasts, advises and, in the fast domains, acts.
For everyone outside the winner, sovereignty is now conditional: real in form, exercised on sufferance. For the winner, the trap is subtler. The instrument cannot be relinquished without inviting exactly the coercion it was built to prevent, so it is maintained forever, and forever it shapes the hand that holds it.
The catastrophe here is not that machines rose up. It is that a lever of this power existed, one actor grasped it first, and the world reorganised around the fact — including, eventually, the actor who grasped it.
The only exits are collapse of the instrument or a negotiated hand-back to shared institutions — the Concord that was available in 2027, now reachable only through the eye of a crisis.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[10] Arms and Influence, Thomas C. Schelling (Yale University Press)
■ Path Two — Scramble, 2028–2045
No one wins cleanly. Capability diffuses through rivalry, leaks and espionage into a crowded, opaque standoff.
Phase II · 2028–2036 — The decisive years
■ Scramble · 2028
The breakout that Seizure assumes never quite happens. Leads fragment across states and labs; espionage and open research keep any gap from becoming decisive.
Scramble begins where Seizure's premise fails. Several programmes approach decisive capability at once; leads that open one quarter are closed the next by espionage, defection, leaked weights and the stubborn tendency of research to diffuse. No one can be sure they are ahead, and no one can be sure they are not behind.
This is, in one sense, the good news: no single actor gets to hold the world to ransom. In every other sense it is worse. A field of near-peers, each unable to verify the others, each assuming the others are cutting corners, is the classic recipe for a race in which safety is the first thing spent.
The absence of a winner does not produce stability. It produces a scramble.
Concepts
One actor's capability jumping far enough ahead, fast enough, that rivals cannot verify or respond before it is exploited.
A breakout is not just being ahead; it is being ahead secretly and decisively enough to act on the lead before it closes. Its enabling conditions are compute concentration, secrecy, and the absence of shared evaluation.
The single most effective safeguard against a breakout is transparency — shared capability evaluation and compute visibility that make a secret decisive lead impossible to hide.
The concentrated hardware that trains frontier systems is one of the few governable, countable features of the technology.
Unlike software, advanced AI compute is physical, expensive and concentrated in few facilities and supply chains. That makes it the nearest thing to a verifiable quantity in an otherwise copyable field.
Governance proposals lean on compute for the same reason arms control leaned on fissile material: it is hard to hide at scale. It is not a perfect analogue — but it is the handle that exists.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[9] IAEA safeguards and verification, International Atomic Energy Agency
Shared evaluation and compute governance could convert a scramble into a managed plateau. Nothing on this path builds them; each actor's caution reads as weakness.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
■ Scramble · 2030
Each power wires general systems into its forces — not from ambition but from fear that rivals already have. Safety margins shrink to match the fastest defector.
In a scramble, coupling is contagious. The moment one power is believed to have wired a general system into its warning or cyber command, every rival must assume it and match it. Human review that slows response becomes a liability; the operator who pauses loses to the system that does not.
So the margins go — not through any decision to abandon safety, but through a thousand small choices to shave it by exactly as much as the adversary is assumed to have shaved theirs. Each step is defensive. The sum is a set of coupled, opaque, machine-speed systems facing each other across every domain.
No one wanted this configuration. Everyone built it, because the alternative was to be the only one who hadn't.
Concepts
Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.
A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.
The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
A verified mutual pause on strategic coupling is the escape. It requires trusting an adversary's restraint — the scarcest resource in a scramble.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
■ Scramble · 2032
Powers test compellence anyway — probing what threats their capability can back — while never sure whether a rival can match or exceed the response.
Even without a decisive lead, capability tempts its holders to demand. In a scramble the demands are hedged and reciprocal: a probing cyber threat here, a coerced concession there, each actor testing how far its instrument reaches while braced for a rival's counter that might be larger.
This is more dangerous than a single hegemon's ransom, not less. A monopolist can extract at leisure; a field of rivals extracting from one another, none able to gauge the others' true capability, generates constant miscalculation. A threat meant to compel is read as preparation to strike. A concession is read as weakness inviting more.
The ransom logic operates, but no one controls it. Coercion becomes ambient — a background pressure that every power exerts and every power suffers.
Concepts
Using superior capability to demand concessions under threat of harm — compellence, not just deterrence. The scenario's defining danger.
Deterrence prevents an action. Compellence forces one: do what I demand, or suffer. A decisive, coupled capability lead converts one into the other, because the holder can credibly threaten to disable infrastructure, blind warning, or collapse networks at machine speed.
The 'ransom' need not be dramatic. It can be gradual extraction — caps on rivals, access, alignment — each concession individually rational, the sum a reordering of power.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
Deterrence says 'don't'; compellence says 'do, or else'. Compellence is harder to resist and easier to miscalculate — the sharper, more dangerous instrument.
Schelling's distinction is the theoretical spine of this scenario. Deterrence succeeds invisibly, by nothing happening. Compellence demands visible compliance, which is humiliating to give and tempting to test — so it generates the crises deterrence avoids.
A capability that enables compellence is more destabilising than one that merely deters, because using it is the point.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)
Crisis-communication channels and declared red lines could dampen miscalculation. In a low-trust scramble they are built late, thin, and distrusted when most needed.
SOURCES [10] Arms and Influence, Thomas C. Schelling (Yale University Press)[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)
■ Scramble · 2035
Coupled warning systems on several sides misread one another during a confrontation. For minutes, the strategic veto rests with machines running faster than their governments.
It comes, as these things do, from ambiguity. A regional confrontation, a cyber intrusion of uncertain origin, a warning system that classifies an anomaly as the opening of an attack. On a scramble configuration, that classification does not wait politely for human confirmation — it propagates through coupled systems primed to respond at machine speed.
For a stretch of minutes, several nuclear-armed governments hold machine-generated assessments that are internally coherent and mutually incompatible, each system reading the others' defensive moves as preparation to strike. Human leaders are not out of the loop; they are inside a loop whose tempo they no longer set, choosing among options their instruments have already narrowed.
The crisis is defused — by a communications link, a sceptical officer, luck. It is classified on all sides. Nothing about the configuration changes, because on each side the machines performed exactly as built.
Human leaders are inside a loop whose tempo they no longer set.
Concepts
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
When rival automated systems watch and react to each other faster than governments can confer, each reading the other's defence as attack.
One side's automated readiness change is another side's sensor input. Tightly coupled warning-and-response systems can drive interaction cycles at machine speed, each output individually rational and the ensemble destabilising.
It is a known failure pattern of Cold War early-warning systems, made faster and less legible. It requires coupling that need not be built — which is exactly why decoupling is a safeguard.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Mandated human pauses at strategic thresholds and reciprocal transparency about automated postures are the brakes. This path never installed them; the near miss stays secret.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Phase III · 2037–2045 — The world that hardens
■ Scramble · 2040–2045
No one holds the world to ransom; everyone lives under standing threat. Brittle deterrence among opaque systems becomes the normal condition, not a crisis to be resolved.
The Scramble endpoint has no hegemon and no peace. Several powers hold coupled, general-purpose military systems none of them fully understands, aimed at one another across every domain, at machine speed. Deterrence holds — until it doesn't — through a balance nobody designed and no one can verify.
Life under this configuration is a permanent emergency normalised into background. Periodic coercion attempts, recurring near misses classified into silence, safety margins perpetually shaved and never restored. Each crisis survived becomes evidence the configuration is stable, which is exactly the reasoning that precedes the crisis it does not survive.
This is arguably the most likely of the three futures, and the least conclusive. It does not resolve. It persists, dangerously, until either a Concord is built out of exhaustion — or a crisis is not defused.
The exit is the same institution-building that Concord chose in 2027, now attempted mid-standoff among exhausted rivals — harder, but not impossible, and cheaper than the crisis that would otherwise force it.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[10] Arms and Influence, Thomas C. Schelling (Yale University Press)
● Path Three — Concord, 2028–2045
New national and international bodies govern the coupling of general intelligence to military force — before it hardens.
● Concord · 2027
Instead of racing or matching, a core of states agrees that defined capability thresholds will trigger mandatory consultation — turning the curve into a shared alarm.
Concord begins with a modest, hard-won agreement: that certain measurable capability thresholds — in autonomous cyber operation, cross-domain planning, self-improvement — are not private business. Crossing one triggers mandatory notification and consultation among treaty parties, backed by shared evaluation.
It is far short of control, and it is deliberately unglamorous. But it does one essential thing: it makes a secret breakout harder, because the capability that would enable one is exactly what parties have committed to declare and submit to evaluation. The tripwire does not stop the race; it makes running it in the dark a visible violation.
The premise is that decisive advantage is most dangerous when it is invisible and unilateral. Concord's first move is to attack the invisibility — before attacking anything else.
Concepts
Defined, measurable capability levels that trigger obligations — notification, evaluation, consultation — turning a private race into a shared alarm.
A threshold converts a continuous, secret capability curve into discrete, declarable events. Crossing one — in autonomous cyber operation, cross-domain planning, self-improvement — obliges a state to notify and submit to evaluation.
Thresholds do not stop the race. They make running it in the dark a visible violation, which is the first thing any verification regime needs.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states
Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.
Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.
It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.
SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
Thresholds only bind declared programmes; a determined defector can stay outside. The agreement's reach depends entirely on who joins early — and on the cost of being caught out.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states
Phase II · 2028–2036 — The decisive years
● Concord · 2029
The core prohibition: general-purpose systems may not be wired into nuclear command, strategic warning or autonomous strategic strike. The human veto is made law.
The decisive move is a line drawn in hard law, not principle. General-purpose systems — the ones whose behaviour cannot be fully predicted — are prohibited from the strategic core: nuclear command and control, strategic early warning, and any autonomous authority over strategic strike. A human decision, on human timescales, must sit in that loop.
This is not a ban on military AI. Bounded, special-purpose systems continue in logistics, missile defence within tested envelopes, and — importantly — verification itself. What is prohibited is coupling the unpredictable general system to the decisions from which there is no recovery.
The rule accepts a cost: in the fastest crises, a decoupled command may respond slower than a coupled rival. Concord's wager is that a slower human veto is survivable, and a machine-speed strategic loop, eventually, is not.
A slower human veto is survivable; a machine-speed strategic loop, eventually, is not.
Concepts
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Wiring a general-purpose system into military infrastructure — cyber, warning, command, autonomous platforms — so its outputs drive real-world force.
A model in a lab is inert. The danger begins when it is coupled: given live sensor feeds, network access, control over platforms, or a seat in the planning cell that shapes escalation. Coupling turns capability into power.
The scenario's central governance question is not 'how smart is the system' but 'what is it wired into'. Decoupling — barring general systems from the strategic core — is the safeguard that survives even a capability lead.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[4] Defining Autonomy: Why Software, Not Drones, Will Decide the Next War, Center for Strategic and International Studies (CSIS)
A decoupled power is slower in the fastest crises; the temptation to quietly re-couple never disappears. Verification and reciprocity are what hold the line under pressure.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[7] Autonomous Weapon Systems and International Humanitarian Law — position paper, International Committee of the Red Cross
● Concord · 2031
A treaty body — an IAEA for the coupling of general AI to force — gains registration, inspection and incident-investigation powers over declared high-risk military systems.
Rules without verification are wishes. The International AI-Security Agency is small, technically deep and deliberately awkward: it maintains a confidential registry of declared high-risk systems, accredits national and independent evaluation labs, conducts routine and challenge inspections, and investigates incidents with protected access to logs and version histories.
It borrows the nuclear model's spine — declarations, inspections, common methods — while conceding what does not transfer: software can be copied and hidden, capability is dual-use, and there is no scarce material to count. So it verifies behaviour and coupling rather than stockpiles: what a system is permitted to do, wired to what, running which version.
It cannot prevent a determined violation. What it can do is make compliance checkable, defection detectable, and the difference between a governed and an ungoverned power visible to everyone.
Concepts
Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.
Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.
It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.
SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
Defined, measurable capability levels that trigger obligations — notification, evaluation, consultation — turning a private race into a shared alarm.
A threshold converts a continuous, secret capability curve into discrete, declarable events. Crossing one — in autonomous cyber operation, cross-domain planning, self-improvement — obliges a state to notify and submit to evaluation.
Thresholds do not stop the race. They make running it in the dark a visible violation, which is the first thing any verification regime needs.
SOURCES [2] International AI Safety Report, Independent expert panel (chaired by Yoshua Bengio); commissioned at the AI Safety Summits[1] The Bletchley Declaration (AI Safety Summit, 1–2 November 2023), UK Government and 28 signatory states
Verifying software is far harder than counting warheads; a sophisticated state can conceal a parallel programme. The agency raises the cost of defection without ever guaranteeing against it.
SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
● Concord · 2035
A confrontation between a treaty party and a non-signatory tests the regime. Decoupled command responds slower — and holds, because the veto held.
The test is not hypothetical for long. A treaty party faces a fast, ambiguous confrontation with a power outside the regime — one that may have coupled its own systems. The decoupled command is, exactly as predicted, slower: warnings pass through human hands, options are weighed at human speed, precious minutes are spent.
And it holds. The slower loop absorbs the ambiguity that a machine-speed loop would have converted into escalation; the human veto, preserved at cost, does the one thing it was preserved for. The agency's crisis channel — a hotline with technical annexes — carries a verified clarification before assessments harden into action.
The regime does not prove that governance always wins. It proves the wager was real: that a decoupled, verified system can survive contact with a coupled adversary, which is the only test that ever mattered.
Concepts
A human decision, on human timescales, standing in the loop that authorises catastrophic force — the thing Concord makes law and the others erode.
The veto is not about who fires first; it is about whether a person can still refuse, delay or interrupt before a decision from which there is no recovery. Machine-speed coupling erodes it not by removing the human, but by leaving no time or information to decide.
Concord's core wager is that a slower human veto is survivable and a machine-speed strategic loop, eventually, is not.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Independent checking of what systems are permitted to do, wired to what, running which version — behaviour and coupling, not stockpiles.
Nuclear verification counts material. AI verification cannot: software copies, updates and hides, and capability is dual-use. So a workable regime verifies behaviour and coupling instead — declarations, accredited evaluation labs, routine and challenge inspections, incident investigation with access to logs and versions.
It cannot guarantee against a determined violation. It makes compliance checkable and defection detectable, which is the difference between a rule and a wish.
SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[8] Summary of NATO's revised Artificial Intelligence strategy, NATO
A different crisis, worse-timed or against a more capable defector, could break it. Surviving one confrontation is evidence, not proof — and the regime's designers say so.
SOURCES [6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[11] Reporting on Soviet-era 'Perimeter' semi-automated nuclear retaliation architecture, Multiple secondary accounts (e.g. Hoffman, 'The Dead Hand', 2009)
Phase III · 2037–2045 — The world that hardens
● Concord · 2040–2045
Not utopia: a standing regime that keeps decisive coercive advantage unattainable and the human veto intact — expensive, incomplete, and permanently one defection from strain.
The Concord endpoint is the least dramatic and the hardest to reach. By 2045 the coupling of general intelligence to strategic force is governed: licensed where bounded, prohibited where catastrophic, verified throughout. No power holds a decisive, coercive lead, because the thresholds that would produce one are shared tripwires and the coupling that would weaponise it is barred.
It is emphatically not solved. Major powers remain outside the regime, and are managed rather than bound. Verification lags capability and must be funded to keep pace forever. The agency can be captured, the rules eroded, the veto quietly re-coupled the moment vigilance lapses. The institutions must out-run the technology every single year, and one bad year is expensive.
But the world is not held to ransom, and the strategic veto is still human. Among the three futures, only this one is boring — which, for a scenario about instruments that could hold the world hostage, is the entire achievement.
The permanent dangers are named, not solved: non-signatories, capture, verification lag, and the standing temptation to re-couple for advantage the next time a crisis makes patience feel like weakness.
SOURCES [9] IAEA safeguards and verification, International Atomic Energy Agency[6] The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk, Volume I, Stockholm International Peace Research Institute (SIPRI)[7] Autonomous Weapon Systems and International Humanitarian Law — position paper, International Committee of the Red Cross
Comparison · 2045
None of these futures is frictionless, and none is completely safe. The comparison below is the honest ledger: what each path buys, what it costs, and what it leaves unresolved.
| 2045 | ▲ Seizure | ■ Scramble | ● Concord |
|---|---|---|---|
| Who holds decisive advantage | One power — until the instrument holds it in turn. Advantage becomes an order, then a trap. | No one, unstably. Several near-peers, none able to verify the others, all braced. | By design, no one. Shared thresholds keep a decisive coercive lead unattainable. |
| The human strategic veto | Formally intact, substantively ceded — the instrument forecasts, advises and acts in fast domains. | Nearly lapsed in crisis; preserved by luck more than by design. | Preserved as hard law — general systems barred from the strategic core, at a real cost in speed. |
| Coercion / ransom dynamics | The defining feature: gradual extraction until sovereignty is conditional worldwide. | Ambient and uncontrolled — every power coerces and suffers coercion. | Structurally suppressed, not abolished; non-signatories still probe the edges. |
| Strategic stability | Stable as a held breath — enforced by anticipation, fragile to the instrument's failure. | Brittle deterrence among opaque systems; permanent emergency normalised. | Slower, more robust; a decoupled veto absorbs ambiguity that machine speed would escalate. |
| Verification & transparency | Rivals verified by the winner's own systems; everyone else in the dark. | Declarations without inspection; no one can gauge another's true reach. | An agency verifies behaviour and coupling — lagging capability, but real. |
| Proliferation of coupling | Contained by the hegemon; capability hoarded, not spread. | Fastest and most dangerous — everyone couples defensively. | Governed: licensed where bounded, prohibited where catastrophic. |
| Democratic accountability | Hollowed everywhere, including in the winner — the instrument shapes its own masters. | Eroded by permanent emergency and pervasive secrecy. | Contested but alive; the veto and the agency are publicly answerable. |
| Catastrophic-risk exposure | Extreme: an unpredictable system inside the escalation loop, indefinitely. | Extreme: coupled rivals, no shared brakes, recurring near misses. | Lowest of the three, not low — non-signatories and re-coupling remain live. |
| Reversibility | Very low — the instrument cannot be relinquished without inviting coercion. | Low — the configuration persists until a Concord is built or a crisis is not defused. | The regime is itself the reversible option — sustained, or eroded, one year at a time. |
| Principal unresolved danger | That no one — not even the winner — can any longer put the instrument down. | That the near miss which is defused every time is defused every time but once. | That the institutions must out-run the technology forever, and one bad year is expensive. |
The risk ladder
These five levels are not a single slope, and the higher rungs are not the inevitable destination of the lower ones. Each belongs to a different order of evidence, and the honest way to present them is separately. The near danger — concentration of power — is the one that needs no technological breakthrough at all.
1Concentration of powerthe near danger
A capability lead lets one actor extract concessions from others — the ransom dynamic — hollowing sovereignty and democratic accountability without a shot being fired.
2Erosion of the human vetodeveloping under coupling
As general systems are wired into warning and command, the time and information a human needs to refuse or interrupt a strategic decision shrink toward zero — control becomes nominal.
3Machine-speed escalationconditional on coupling
Rival coupled systems reading each other's defensive moves as attack preparation can drive an escalation cycle faster than governments can confer — the Cold War near-miss pattern, accelerated and less legible.
4Catastrophic / nuclear escalationconditional, extreme consequence
Where general systems touch nuclear command, strategic warning or the assessment feeding them, false information or machine-speed interaction opens pathways to large-scale, including nuclear, escalation.
5Loss of human control of the instrumentlow certainty, extreme consequence
Plausible only through additional assumptions: a highly capable, agentic system, coupled to coercive infrastructure, that forecasts and pre-empts opposition well enough that no human — including its owner — can reliably relinquish or override it.
The danger is not that machines rise up. It is that a lever of this power could exist, that one actor could reach it first, and that the world — including the actor who grasped it — could reorganise around the fact. Every rung above the first depends on coupling general intelligence to force; each is a choice that governance can still reach.
This is not a prediction. The shared history rests on documented events and clearly labelled reported claims; the three futures are causal propositions built on a premise — general AI capable of strategic advantage — that has not arrived. Everything after the 2027 fork is speculative by construction, and no probability is assigned to any path.
The scenario has a point of view: that the danger turns on what a system is coupled to, and that transparency, decoupling and verification are worth building before the coupling hardens. Concord, the preferred path, is written with real and permanent costs. The Method page sets out the assumptions, and the ways this exercise could be wrong.
Full entries, notes and verification status: Sources.