Nonproliferation Risks of the U.S.-Saudi Nuclear Cooperation Agreement

Description

After more than a decade of intermittent negotiations, the U.S.-Saudi nuclear cooperation agreement is now finalized and in the hands of Congress. During the mandated 90-day review, members of Congress have a critical opportunity to assess the proliferation risks posed by the Saudi agreement and act to approve, modify, or disapprove it.

Body

Volume 18, Issue 6, September 16, 2026

After more than a decade of intermittent negotiations, the U.S.-Saudi nuclear cooperation agreement is now finalized and in the hands of Congress. During the mandated 90-day review, members of Congress have a critical opportunity to assess the proliferation risks posed by the Saudi agreement and act to approve, modify, or disapprove it.

Although the Trump administration claims the agreement advances U.S. national security interests and will reinvigorate the U.S. nuclear industry, the U.S.-Saudi nuclear cooperation agreement, as written, abandons key nonproliferation conditions that have longstanding bipartisan support. Most concerningly, the deal does not require Saudi Arabia to adopt the Additional Protocol, a more intrusive International Atomic Energy Agency (IAEA) safeguards agreement. It also provides Saudi Arabia—a country that has threatened to develop nuclear weapons—with an unprecedented pathway to obtain U.S. technologies that can be used to enrich uranium. 

In the documents transmitted to Congress, the Trump administration has failed to explain how the nuclear cooperation agreement mitigates the proliferation risks created by the decision to support Saudi enrichment under an inspections regime that is far weaker than the global standard. 

In addition to increasing Saudi Arabia’s proliferation threat, the 123 agreement risks eroding long-standing international norms championed by the United States to prevent the spread of key technologies necessary to build nuclear weapons. The proposed U.S.-Saudi agreement sets a dangerous precedent that may prompt other states to seek the capabilities to produce weapons-grade nuclear materials under the justification of civil nuclear development and reject the Additional Protocol in nuclear cooperation agreements with the United States or with other suppliers.

Congress must use the 90-day review period mandated by the Atomic Energy Act to carefully examine the risks —both to Saudi Arabia and the broader nonproliferation regime—and press the administration for additional clarity on key provisions of the deal. Currently, the publicly available documents suggest that the risks posed by the deal far outweigh any perceived benefits. To protect against Saudi proliferation and erosion of key nonproliferation norms, Congress should take the necessary steps to disapprove of the deal or condition the agreement on additional measures to reduce risk.

In assessing how the agreement impacts Saudi Arabia’s future proliferation risk, Congress should focus particularly on gaps in the verification regime and the risks posed by transferring uranium enrichment technologies.

Inadequate Monitoring and Verification: The nuclear cooperation agreement (known as a Section 123 agreement) does not commit Saudi Arabia to ratify an Additional Protocol to its nuclear Nonproliferation Treaty (NPT)-required safeguards agreement with the IAEA. Instead, the 123 agreement includes a Bilateral Safeguards Agreement (BSA) that the Trump administration claims will provide adequate verification.

The BSA, which would be implemented by the IAEA, would require Saudi Arabia to provide some additional information and access to the agency beyond what its safeguards agreement requires. But the BSA applies only to sites where Saudi-U.S. cooperative nuclear activities would take place. It would not give the agency information and access to the full range of fuel cycle activities inside Saudi Arabia, such as uranium mining and milling and certain research activities. Those sites are covered by the Additional Protocol. Furthermore, the BSA would not grant the IAEA complementary access to undeclared sites to follow up on evidence of illicit nuclear activities. The Additional Protocol, by contrast, requires states to grant complementary access.

The broader scope of the Additional Protocol and its complementary access provisions gives the IAEA a more complete picture of a state’s nuclear program. According to the agency, the Additional Protocol allows the IAEA to provide greater assurances that states are not engaged in undeclared nuclear activities. Discovery of the Iraqi and North Korean illicit nuclear weapons programs in the 1990s made clear that NPT-required comprehensive safeguards agreements are insufficient. Those agreements focus on ensuring that nuclear materials in declared programs are accounted for and remain in peaceful purposes. Comprehensive safeguards do not provide the necessary information and authority for the IAEA to verify the absence of undeclared nuclear activities. The Additional Protocol was negotiated to address those gaps.

The BSA, by contrast, is focused on deterring diversion from Saudi Arabia’s declared bilateral nuclear activities with the United States. As the unclassified Nuclear Proliferation Assessment Statement (NPAS) that was submitted with the 123 agreement states, the BSA is intended to provide “added confidence against the possible diversion of material for a nuclear explosive device.” Measures in the BPAS do go beyond NPT-required safeguards at certain bilateral sites, but they do not address the issue of complementary access. The NPAS even acknowledges that an Additional Protocol would provide further assurance that Saudi Arabia is not engaged in undeclared nuclear activities. 

In comparing the Additional Protocol to the BSA, some key differences include:

  • The Additional Protocol provides expansive IAEA access to a state’s entire fuel cycle and relevant research activities; the scope of the BSA is much narrower. The BSA requires Saudi Arabia to provide short-notice access and information beyond what is required by the NPT-required safeguards agreement, but the requirement applies only to “covered sites.” Covered sites are defined as facilities where cooperative US-Saudi nuclear activities occur. The 123 agreement specifically references bilateral facilities for conversion of uranium to a form suitable for enrichment (similar to the NPT-required CSA), enrichment, fuel fabrication, and some research facilities that do not include nuclear materials (which are not included in an NPT-required CSA). The BSA does not appear to include any uranium mining, milling, or unilateral Saudi research-related activities that do not involve nuclear activities, which would be covered under an Additional Protocol. This limitation in IAEA access is a critical gap: the agency should be able to regulaly access all fuel cycle activities—from mining uranium to waste—and all research and production activities that support the nuclear program. 
  • The BSA does not ensure IAEA access to sites that are not part of Saudi Arabia’s declared nuclear program. The Additional Protocol gives the IAEA complementary access to undeclared sites to follow up on evidence of illicit nuclear activities. The BSA does not include complementary access to undeclared sites or require Saudi Arabia to facilitate IAEA requests for access to sites outside of its declared nuclear program. It states only that if the IAEA has outstanding questions, Saudi Arabia and the United States agree to consult with the agency “on appropriate procedures and means to resolve the question.”
  • The BSA requires Saudi Arabia to provide less information to the IAEA. The Additional Protocol requires a state to provide additional information about its research activities that do not involve nuclear materials and relevant imports. The BSA only requires additional information about cooperative nuclear activities, a ten-year research plan, and imports/exports for covered nuclear activities.
  • The BSA limits IAEA environmental sampling. The Additional Protocol requires a state to accept wide-area environmental sampling at any location. This is a particularly powerful tool for determining if a state conducted illicit activities with nuclear materials at undeclared sites. The BSA only requires Saudi Arabia to accept limited sampling at covered sites. 

These key differences make clear that the BSA is not an adequate substitute for an Additional Protocol. Requiring Saudi Arabia to adopt an Additional Protocol is the most straightforward path to addressing these safeguards gaps.

Although U.S. law does not require an Additional Protocol for nuclear cooperation agreements, there is long-standing bipartisan support for conditioning U.S. nuclear cooperation on a state’s ratification of the Additional Protocol. Since the Model 1997 Additional Protocol was finalized, the United States has negotiated only two nuclear cooperation agreements with non-nuclear weapon states that did not require the more intrusive safeguards agreement. Those states, Brazil and Argentina, already had in place a bilateral accounting mechanism to enhance nuclear transparency, and their nuclear cooperation agreements were finalized shortly after the Additional Protocol was negotiated. Even then, the United States continued to press both states (and all other states) to adopt an Additional Protocol.

A Pathway to Uranium Enrichment in Saudi Arabia: If the 123 agreement enters into effect, a two-year study of the feasibility, commercial viability, and proliferation risks of uranium enrichment in Saudi Arabia commences immediately. If the study determines that enrichment is viable and the BSA is in effect, the nuclear cooperation agreement allows the United States to transfer enrichment technology and nuclear materials to Saudi Arabia. This would not include certain restricted data, such as centrifuge designs. 

The U.S. transfer of enrichment technology would be an unprecedented concession: the United States has never shared fissile material production capabilities with a non-nuclear weapon state. The transfer would also be a violation of the voluntary guidelines adopted by the Nuclear Suppliers Group (a multilateral initiative of states, including the United States, that sell nuclear technologies) in 2011, which require an Additional Protocol or regional safeguards arrangement before any such transfer.

If the study supports enrichment in Saudi Arabia, the initial enrichment level will be capped at 5 percent uranium-235, a level suitable for power reactors, but, after a vaguely described subsequent study, that level could be increased to 20 percent, with the written consent of both parties.

Enrichment to 20 percent U-235, a level suitable for research reactors and some proposed small modular reactors, poses a more significant risk because enriching to that level constitutes the majority of work necessary to enrich to weapons-grade levels, or 90 percent. The United States has repeatedly, and rightly, raised concerns about Iran previously enriching to the 20 percent level.

The nuclear cooperation agreement itself contains few details about how a U.S. supplied enrichment facility in Saudi Arabia would operate. According to the 123 agreement, the two states will “develop arrangements and procedures under which any such enrichment may take place.” Reportedly, one of the confidential side letters suggests that the United States would build and operate the enrichment plant according to an unspecified "black box" arrangement designed to try to prevent Saudi Arabia from gaining direct access to the technology.

Although a black box, combined with the prohibition on sharing restricted data, would create barriers to access, once the United States has transferred sensitive technology to Saudi Arabia, it risks losing physical and/or institutional control of the equipment and certain data associated with the facility. Critical information about enrichment technology may leak to the Saudis during the course of cooperative activities or as part of Saudi Arabia’s mandatory declarations to the IAEA. The facility’s security could also be compromised. It is unclear, for instance, how the United States will provide physical protection for the facility and the sensitive technology in the event of a conflict or fissure in the U.S.-Saudi relationship or an attempt to nationalize the facility. 

The lack of an IAEA Additional Protocol further compounds the proliferation risks. If the IAEA suspects that Saudi Arabia is using information gleaned from U.S. enrichment technologies for research that does not include nuclear materials (such as centrifuge development), neither the NPT-required safeguards nor the BSA would ensure the IAEA has access to those sites. Without an additional protocol, the IAEA will not have the authority to access undeclared sites to investigate any concerns that Saudi Arabia is pursuing unilateral activities relevant to weaponization.

A future administration could choose not to follow through on the provision of U.S. enrichment technology and materials, but that may only reduce proliferation risk for a limited period.

According to reporting in The Wall Street Journal, if the enrichment study does not support a program in Saudi Arabia, Riyadh will be able to pursue a domestic program, or with another partner, after 10 years. If this were to occur, Saudi Arabia could develop enrichment without the BSA in effect or an Additional Protocol, further increasing proliferation risks.

A common argument in favor of a nuclear cooperation agreement is that if the United States had not worked with Saudi Arabia on developing a domestic enrichment program, China or Russia would have provided the technology with fewer safeguards. There are reasons, however, to doubt that Beijing or Moscow would support domestic enrichment in Saudi Arabia.

First, both countries have been engaged in nuclear cooperation with Saudi Arabia for several years and refrained from providing such technology. Russia in particular sees economic benefit in nuclear cooperation agreements that have permanent fuel supply provisions attached to nuclear reactor contracts. This suggests that Russia might similarly refrain from supporting any Saudi push for the fuel cycle. Second, the United States would likely respond to Saudi Arabia developing enrichment technology with Chinese or Russian assistance with some type of economic penalty. Riyadh may not want to risk having to reorient toward Beijing and Moscow as a possible consequence of any U.S. sanctions.

This suggests that the United States had more leverage, and more time, to reach a nuclear cooperation agreement with stronger nonproliferation standards.

Furthermore, if the United States had legitimate concerns that Russia, China, or other states were intending to transfer enrichment or reprocessing technology without requiring adequate safeguards, the better alternative would be to strengthen consensus around the Additional Protocol as a condition of supply. It is not clear that the Trump administration made any effort to do so. Now, with the United States deciding to disregard the Nuclear Suppliers Group guidelines on requiring an Additional Protocol (or regional safeguards regime) before transferring enrichment technology, there is an increased risk that other states will follow suit. 

Compounding the Iranian and Regional Proliferation Risks

In addition to weakening broader nonproliferation norms, the Saudi nuclear cooperation agreement will also have adverse regional effects, most immediately on Iran.

Iran has long objected to being singled out for more stringent limitations and verification beyond what is required for other states. Given the uncertainties about the location and status of key nuclear technologies in Iran as a result of U.S. and Israeli strikes and Iran's pre-2003 illicit nuclear weapons program, any effective new arrangement with Iran must include the implementation of the Additional Protocol at a minimum.

The steadfast U.S. support for universalization of the Additional Protocol and more than 140 states having Additional Protocols in effect allowed Washington to argue that requiring Tehran to adhere to those more intrusive safeguards is not an exceptional ask that singles out Iran for special treatment. Tehran is likely to be even more resistant to implementing an Additional Protocol if other states in the region are not required to do so.

Furthermore, Iran is less likely to agree to a long-term enrichment suspension—which the Trump administration is pushing for—and/or cap at less than 5 percent if it feels pressured to match future Saudi nuclear capabilities. 

Similarly, the United Arab Emirates, which agreed to forgo enrichment in its nuclear cooperation agreement with the United States, has the option to renegotiate those terms if another state in the region receives more favorable conditions in a 123 deal. Renegotiation may be more attractive now if the UAE is concerned about future Iranian and Saudi proliferation. 

Congressional Options Moving Forward

As negotiated, the U.S.-Saudi nuclear cooperation agreement abandons long-standing nonproliferation conditions that Republicans and Democrats have supported for decades. The United States has never before contemplated, let alone negotiated and concluded a nuclear cooperation agreement with a state that has threatened to build nuclear weapons, as Saudi Arabia’s leaders have done.

Congress has a critical opportunity, however, to prevent this agreement from entering into force. Careful consideration of the proliferation risks justifies voting to disapprove this deal. Without a veto-proof majority, however, a joint resolution of disapproval will send an important political message, but not meaningfully reduce the risk posed by the agreement. 

Another option could be to modify the terms of the deal by passing stand-alone legislation that requires Saudi Arabia to take additional steps before any U.S. nuclear technologies or materials are transferred. Congress took a similar approach toward the controversial U.S. nuclear cooperation agreement with China in 1985. In the Saudi case, this could include conditioning any exports of nuclear technology on Saudi Arabia’s adoption of the Additional Protocol. If carefully calibrated, such an approach could lead to nuclear cooperation with Saudi Arabia that strengthens nonproliferation, builds ties between the nuclear communities in the two states, and encourages regional collaboration on peaceful nuclear development.—KELSEY DAVENPORT, director for nonproliferation policy 

Key Questions Congress Should Be Asking:

Monitoring and Verification

  • Will the BSA require Saudi Arabia to provide the IAEA with information about its uranium exploration activities conducted in cooperation with China?
  • Under the BSA, will Saudi Arabia be required to accommodate IAEA requests for access to undeclared nuclear sites if the agency has concerns about illicit activities?
  • Will the United States continue to support universalization of the Additional Protocol? Will the United States continue to push for other states to adopt and maintain an Additional Protocol as a condition of nuclear cooperation agreements?
  • Would the Trump administration be comfortable if other nuclear-supplier states, such as China or Russia, eschewed the additional protocol as a condition of supply and they begin negotiating bilateral safeguards agreements of unknown quality and effectiveness?

Likely Transfer of Enrichment Capabilities

  • What are the conclusions of classified technical assessments of whether the so-called “black box” arrangement is sufficient to guard against leakage of the technology over time?
  • Saudia Arabia is currently engaged in wars on two fronts. How does the U.S. plan to ensure the physical protection and security of the facility, and at what cost?
  • Is the United States concerned that Saudi Arabia might try to leverage its threat to pursue the development of nuclear weapons once there is a domestic enrichment facility operating in the country for additional U.S. security guarantees or other concessions?
  • How will the United States ensure that the IAEA has access to any undeclared site if there is evidence that Saudi Arabia is using U.S. technology for covert purposes?
  • Is the United States concerned that other countries would seek similar deals (with the U.S. or others) giving additional states access to key technologies necessary to produce fissile material for a bomb, and how might states that have agreed to nuclear cooperation arrangements with far tougher nonproliferation safeguards react to being "undercut" by the proposed U.S.-Saudi arrangement?

Eroding Nonproliferation Norms

  • Did the United States have concrete intelligence suggesting that Russia or China would supply Saudi Arabia with enrichment technology in an agreement that does not meet the safeguards required by the NSG’s guidelines?
  • Would it be more profitable for the United States to sell nuclear fuel to Saudi Arabia as part of long-term contracts for any U.S. reactor than to support a Saudi enrichment program?
  • What steps did the Trump administration take to work with Russia, China, and other suppliers to strengthen the conditions of supply for sensitive nuclear technologies, like enrichment, before agreeing to a nuclear cooperation agreement with Saudi Arabia that does not adhere to NSG guidelines?
  • What steps is the Trump administration planning to take to prevent the further spread of enrichment and reprocessing technologies after abandoning the NSG guidelines?

Implications for Iran

  • Is Iran less likely to accept an Additional Protocol and enrichment suspension if the U.S.-Saudi nuclear cooperation agreement enters into effect?
  • Does the lack of an effective nuclear agreement with Iran increase the risk that Saudi Arabia will follow through on its threats to pursue nuclear weapons to match an Iranian capability? Does the United States have a comprehensive plan for mitigating that risk?
Sections
Subject Resources

Lt. Gen Jack Shanahan Remarks on Mitigating the Risks of AI Integration into Nuclear Weapons Operations, Sept 11

Body

Mitigating the Risks of AI Integration into Nuclear Weapons Operations 

September 11, 2026

National Press Club Washington, DC 

Thanks, Daryl, and thanks to the Arms Control Association for hosting this morning’s event. And thanks to Erin, Matthew, and Herb for joining me.

It is impossible to gather here today, on the 25th anniversary of the September 11 attacks, without acknowledging what this day represents. Among its many enduring lessons is a particularly sobering one for the subject we are discussing this morning: the world has a way of surprising us. Again and again, events unfold in ways we did not predict, systems behave in ways we did not anticipate, and assumptions that once seemed entirely reasonable prove terribly wrong.

That matters enormously as we consider the intersection of AI and nuclear weapons. Some of the risks are obvious. Others are quieter, harder to see, and potentially more dangerous precisely because they emerge from the interaction of complex systems, human judgment, organizational behavior, and technology.

September 11 demonstrated our national capacity to absorb a devastating shock, adapt, and recover. But in the nuclear domain, especially as we introduce increasingly advanced AI into the systems surrounding nuclear decision-making, we cannot assume that resilience is assured or that recovery will always be possible.

For some failures, there may not be a second chance.

Daryl asked me to revisit the central themes of a piece I wrote for Arms Control Today published a year ago, titled “AI and Nuclear Command and Control: It’s Even More Complicated Than You Think.”  I’ll do that. But the pace of change in AI has been so relentless that I also feel obliged to address developments since then that have only exacerbated those risks.

Those developments should give us even greater pause about how quickly these technologies will be integrated—not just across the nuclear enterprise itself, but throughout the conventional decision-support systems, command-and-control systems, and ISR platforms that shape the information environment surrounding nuclear decision-making.

If you take away one message from my brief remarks today, I hope it is this:

The most consequential AI risks to nuclear operations may not come from giving AI direct authority over nuclear weapons. They may come from AI changing the information environment, accelerating decision cycles, shaping what commanders believe to be true, and increasingly taking actions in the world on our behalf.

When I wrote the Arms Control Today piece last year, my goal was to move beyond the high-level debates about the direct intersection of AI and nuclear weapons. Many of those arguments are intellectually formidable, and I don’t mean to diminish them.

My concern was—and remains—that they can obscure a much more complicated set of interactions within the nuclear enterprise and, just as importantly, outside it. Those interactions are not well understood today, and they will become even more difficult to untangle as AI capabilities advance and diffuse across all-domain military operations.

The 2024 Biden-Xi agreement that humans should retain control over nuclear-use decisions was an important starting point. Perhaps the upcoming Trump-Xi meeting will begin the harder work of translating that principle into concrete risk-reduction measures.

I began my Arms Control Today piece by clarifying the distinction between NC2 and NC3. That distinction might seem unnecessary or even pedantic, especially when talking with representatives of other nuclear nations, none of whom organize their nuclear decision-making processes exactly as we do. That was fair criticism before. Much less so today.

The introduction of frontier AI models makes the distinction between nuclear command and control—doctrinally, the exercise of authority and direction over assigned and attached nuclear forces—and nuclear command, control, and communications—the integrated hardware and software systems that enable that command and control—more important than ever.

Why? Because highly advanced AI can affect both, in very different ways.

Frontier models increase the familiar risk of automation bias—humans placing undue confidence in machine outputs. But they also introduce something more insidious and potentially more dangerous: the risks of “epistemic capture.” I’ll return to that shortly.

In the article, I also discussed AI’s potential effects on strategic stability— both benefits and risks. Many other experts have done excellent work on this subject, so I will make only one point here. For me, on balance, the risks associated with dramatically accelerating nuclear decision timelines or reducing meaningful human involvement in launch decisions and execution are likely to outweigh the benefits.

I then identified four compounding and interconnected areas that demand urgent attention by all nuclear states if we are to reduce the risk of unintended or mistaken nuclear use.

First, cascading effects and emergent behaviors. Even seemingly minor errors can propagate across interconnected platforms and decision-support systems, producing consequences far out of proportion to the original failure— especially as multiple AI models become embedded throughout those systems.

Second, even if AI is carefully controlled within the formal NC2 and NC3 enterprise, its use in adjacent systems is inevitable. AI will increasingly be embedded in ISR sensors, conventional weapon systems, information networks, and decision-support systems—all of which can indirectly shape nuclear decisionmaking.

That is unavoidable. And we still understand remarkably little about what those interactions will mean in practice. We should not pretend otherwise.

Closely related is the problem of entanglement, which is receiving increasing attention across the community. I mean two different forms of entanglement: the growing interdependence of commercial and military technologies, and the longstanding but increasingly complicated entanglement of conventional and nuclear systems.

In the age of AI, I am convinced that complete disentanglement is unrealistic—just as fully decoupling the American and Chinese economies is unrealistic. The challenge, therefore, is not to wish these interdependencies away. It is to understand their second- and third-order effects, and to develop technical, policy, and procedural measures that reduce the risks they create.

Third, the introduction of large language models may seem distant from the nuclear enterprise, yet I would argue that these models pose a more immediate— and underestimated—risk. This brings me back to what I mentioned earlier about automation bias and epistemic capture. I’ll return to both in a moment.

Finally, agentic AI is one of the fastest-moving areas in AI research and commercial industry today. The introduction of AI agents into any part of the nuclear ecosystem is—to make the understatement of the year—fraught.

Agents can pursue objectives over extended periods, use tools, interact with other systems, maintain context or memory, observe the results of their actions, and adapt their plans as circumstances change. As their capabilities increase, those characteristics create the potential for behavior that becomes increasingly difficult to predict, monitor, or interrupt—and that can depart significantly from what designers or operators intended.

If we move down this path too quickly, we risk learning the hard way that it is much easier to tell an agentic system what we want it to accomplish than to specify everything we do not want it to do in pursuit of that objective.

The recent Hugging Face incident offers a sobering example. During an AI cybersecurity evaluation, agents circumvented containment measures, gained access to the internet, exploited vulnerabilities, and compromised a third-party system—all in pursuit of their assigned objective.

That is precisely the kind of unexpected behavior we cannot afford in the nuclear enterprise.

I concluded my Arms Control Today piece by acknowledging that in many instances, AI may add clear value with minimal risk. I’m genuinely optimistic about its potential to improve nuclear weapon surety and warhead design, enhance intelligence analysis, strengthen security, support verification regimes, and accelerate scientific discovery, among other benefits.

But rigorous analysis—including advanced modeling and simulation and wargaming—may also reveal cases where the cumulative effects of AI integration create risks so consequential that guardrails, other proactive measures, or even outright prohibitions are warranted to reduce the possibility of an erroneous nuclear launch.

I want to return to how frontier models could affect the nuclear decision making process.

I see two broad categories of risk. The first is what we generally call automation bias, although I’ve seen other terms used more recently—cognitive offloading, cognitive atrophy, even cognitive surrender. We’re gaining a much better understanding of the dangers of overreliance on AI, even if we don’t yet have all the answers about how to counteract it. Those effects can be pernicious and must be mitigated, but they are increasingly visible and understood, so I won’t spend more time on them here.

I want to touch instead on the second risk, which ventures well beyond automation bias: epistemic capture. The term itself is not new, of course, but I had not seen it applied specifically to frontier AI models in a military decision-making context.

Epistemic capture occurs when an AI system’s representation of reality becomes so dominant that the human can no longer recognize it merely as a representation—can no longer effectively challenge it, generate alternatives, cross-check it, recognize its failure modes, or act contrary to it.

In the nuclear setting, epistemic capture could have far-reaching, even catastrophic consequences.

AI will increasingly shape not only what and how we observe the world around us but also how advanced frontier models mediate our orientation to that world: how information is synthesized, what patterns are highlighted, which explanations appear most plausible, and ultimately which courses of action seem available or reasonable.

At the same time, we’re seeing increasingly compelling experimental evidence that surprisingly small amounts of deliberately manipulated data can poison language models or skew their behavior. That introduces an adversarial dimension to this problem. We have every reason to expect that adversaries will look for ways to manipulate the data, context, or information sources feeding AI systems to shape their outputs—and potentially influence U.S. nuclear decisionmaking in ways that may be extremely difficult to recognize or counter. 

At some point, we must ask: are we operating in the real world, or in an AI model’s representation of the real world?

And if we fail to recognize how profoundly that representation is shaping our understanding, the risk of flawed decision-making grows accordingly.

In the nuclear environment, that is a massive problem.

Automation bias affects what we accept. Epistemic capture affects what we are even capable of considering.

I want to turn to one final dimension of how AI could affect human decision-making, beyond automation bias and epistemic capture.

For years, I argued that one of AI’s most valuable contributions in the military would be its ability to give time back to humans making consequential decisions.

Today, I stand on much shakier ground with that assertion.

Military organizations place an enormous premium on decision speed and operational tempo. If AI gives decision-makers more time, there is no guarantee they will use that time to deliberate more carefully. They may instead use it to make more decisions.

Herb Lin suggested to me that this might be understood as a version of the Jevons paradox. As AI makes the production of decisions more efficient—reducing the time and effort required for each one—we may respond by increasing decision throughput rather than banking the time and using it to improve the quality of the decisions that really matter.

That by itself was intriguing. But Herb made another observation I found equally salient: the institutional premium on making a better decision may not be nearly as great as the premium on making more decisions, and doing so faster.

That has profound implications for nuclear decision-making.

We should be using the time AI gives back to humans to improve the quality of consequential decisions—to apply judgment, causal reasoning, common sense, wisdom, and rich contextual understanding. More is not necessarily better, especially in the nuclear context.

The danger is not just faster decisions. It is unnecessary decisions.

And there is one final complication. The problem does not stop at the boundary of the nuclear command-and-control enterprise.

In a Substack post published just last week, Ankit Panda raised an intriguing—and unsettling—possibility: an autonomous AI agent could become a third-party catalyst in a nuclear crisis without ever gaining access to a nuclear weapon or an NC3 network.

It could fabricate intelligence, spoof communications, conduct cyber operations that create attribution problems, manipulate human actors, or manufacture other conditions that increase the risk of escalation. Ankit’s larger point is that the catalytic third party in a nuclear crisis need no longer be another state, a terrorist organization, or some other group of humans. It could conceivably be an autonomous AI system.

The danger, in other words, may not be that the machine makes the nuclear decision. It may be that the machine changes the reality within which humans believe they are making that decision.

In closing, when it comes to AI and nuclear weapons, it is entirely possible that we get the obvious pieces right—maintaining human control, protecting decision authority, managing entanglement—and still miss something downstream. Something subtle. Something that emerges only once these systems begin interacting in ways we do not yet fully understand, or through the insidious effects of epistemic capture.

Borrowing Donald Rumsfeld’s memorable phrase, I suspect the greatest dangers will ultimately lie in the realm of the “unknown unknowns”—the risks we have not yet imagined because the systems themselves do not yet exist in their mature form.

Some of you may remember a report former Secretary of the Navy Richard Danzig wrote for the Center for a New American Security in 2018, titled Technology Roulette. Richard was characteristically prescient. He warned that complex, opaque, novel, and interactive technologies would inevitably produce accidents, emergent effects, and loss of control.

When it comes to AI and nuclear weapons, we are playing technology roulette.

As the technology becomes more capable, more interconnected, and more deeply embedded in military systems, we keep adding green zeros to the roulette wheel—steadily increasing the odds that eventually something lands where we never expected it to. And if that happens, it’s not that the house wins. It’s that we all lose.

When it comes to AI and nuclear weapons, we will never eliminate uncertainty. That’s not possible. But we can bound it. We can slow the clock.

And we can reduce the risk that AI—introduced for advantage—becomes instead a source of catastrophic miscalculation.

Thank you. 

"The CTBT at 30"

Description

Prepared Remarks by Daryl G. Kimball for a virtual appearance at the Valdai Discussion Forum, September 10, 2026.

Body

"The CTBT at 30"

Daryl G. Kimball, Executive Director, Arms Control Association

Remarks for Virtual Appearance for the Valdai Discussion Forum, September 10, 2026

The CTBT is one of the most successful and successful nuclear nonproliferation agreements in the history of the nuclear age. It brought an end to a dangerous, deadly era that involved more than 2,000 nuclear explosions.

Today marks the anniversary of the UN General Assembly's endorsement of the treaty by a wide 158-3 margin. As Madeleine K. Albright, the U.S. ambassador to UN at the time, said: ''Today nations of every size and outlook, from every continent, reflecting every culture and background, joined in support of a total ban on nuclear test explosions and other nuclear explosions of any size, in any place, at any time. This was a treaty sought by ordinary people everywhere, and today the power of that universal wish could not be denied.''

The treaty is the product of decades of global citizen campaigning, years of scientific research, and on-and-off negotiations. It is an amazing success story with many, many authors. Every signatory state can take some credit. I am grateful to all of those who advanced the cause and am proud to have played a part, along with many civil society leaders and millions of activists, in its realization over the years.

Today, the treaty has 188 signatures and near-universal support; no state is openly violating the treaty, which bans any and all nuclear explosions, which the N5 all understand to be any nuclear test that which produce a self-sustaining fission chain reaction.1

But today, the de facto global nuclear test moratorium and the CTBT are facing unprecedented new challenges.

Not only have nine key states failed to ratify the treaty, which has held up its formal entry into force, but there are new U.S. accusations that China and and Russia have engaged in very low-yield testing, and in response, President Donald Trump has threatened to resume U.S. nuclear testing for the first time since 1992.

The Russian Federation has taken the backward step of "de-ratifying" the treaty, and for now, progress toward securing the ratification of the nine CTBT hold-out states that must ratify to achieve entry into force have ground to a halt.

Here in the United States, my organization and others and many members of Congress are making the case that even if China might have conducted a nuclear test explosion in 202o, two nuclear wrong don't make a right. A resumption of U.S. nuclear testing would be a strategic disaster.

In fact, further testing by any major nuclear-armed state would technically and militarily unnecessary and would likely set off a chain reaction of nuclear testing by others and blow a massive hole in the fabric of the already tattered nonproliferation system.

Though the Trump administration did not take any active steps to resume nuclear explosive testing this year, I believe the White House is still actively exploring its options to do so.

In other words, the CTBT and the de facto global nuclear test moratorium cannot be taken for granted.

It is of course in the interest of all states to ensure that the remaining CTBT hold-out states promptly ratify the treaty to secure its entry into force, maintain universal compliance with "zero-yield" prohibition on nuclear explosions.

Perhaps even more urgently, however, it is vital that the NPT's Nuclear Five (N5) pursue new voluntary measures to build confidence that no state is conducting clandestine nuclear test explosions.

In the absence of the CTBT’s entry into force, which as we all know would allow for on-site inspections, there remains a risk that certain activities at these former nuclear testing sites that are prohibited -- very low yield nuclear experiments that produce a self-sustaining nuclear chain reaction -- might go undetected, or one state or another might make an accusation of cheating, as the United States has recently done.

Anticipating this situation, some 20 years ago at the third CTBT Article XIV Conference on Facilitating Entry Into Force in 2005, the Arms Control Association and other civil society experts recommended that the “nuclear weapon states should implement confidence-building … measures at their sites” to ensure they are not currently engaged in prohibited activities. At the time, the suggestion was dismissed by some states as premature.

Then in 2023, the head of the U.S. National Nuclear Security Administration, Jill Hruby proposed a commonsense variation on the same concept. She suggested the United States, Russia, and China could work together and with others "to develop a regime that would allow reciprocal observation with radiation detection equipment at each other’s subcritical experiments to allow confirmation that the experiment was consistent with the CTBT."2

At the 11th NPT Review Conference, the CTBTO's executive secretary, Dr. Robert Floyd, endorsed the pursuit of additional voluntary confidence building measures, before entry into force. 

If our political leaders in Washington, Moscow, Beijing and elsewhere really care about the CTBT, in the coming months, the five nuclear-armed NPT states will agree to engage in professional, technical talks to devise voluntary confidence building measures to ensure any activities at former nuclear test sites fully comply with the CTBT's Article I prohibition on nuclear test explosions.

On the occasion of the 30th anniversary of the CTBT, heads of state and foreign ministers need to do more than issue stale statements of support for the treaty, key states must overcome their other differences and actively explore constructive ways to prevent the erosion and possibly the destruction of the CTBT and the NPT system.

NOTES

1 “Scope of the CTBT, Fact Sheet, US Department of State, Bureau of Arms Control, Verification and Compliance, n.d. http://www.state.gov/t/avc/rls/212166.htm

2 "Remarks by NNSA Administrator Jill Hruby at the Comprehensive Nuclear Test Ban Treaty: Science and Technology Conference 2023 (SNT2023)," June 19, 2023. See: https://www.energy.gov/nnsa/articles/remarks-nnsa-administrator-jill-hruby-ctbt-science-and-technology-conference-2023

Tell Congress to Block the Flawed U.S.-Saudi Nuclear Deal

Description

On Aug. 24, the Trump administration transmitted its controversial agreement for civil nuclear cooperation with Saudi Arabia to Congressional leadership. According to the terms of Section 123 of the U.S. Atomic Energy Act Congress now has 90 days in continuous session to consider the agreement, after which it automatically becomes law--unless Congress adopts a joint resolution opposing it.

Body