The Missing Article
The major arms control treaties of the twentieth century were drafted before the age of AI. They were designed to constrain forces their authors could imagine: nuclear warheads, poison gas, blinding lasers, cluster munitions. None of them anticipated autonomous targeting systems, AI-assisted launch decisions, large language models that could design novel pathogens, or algorithmic surveillance tools sold across borders to suppress dissent.
This initiative proposes a draft Article X for each of seven major treaties. Each Article X is written in the legal register of its parent instrument and also presents a people’s mirror that seeks to extend its mandate to address the specific AI-related gap each treaty leaves open. These are creative provocations intended to serve as a starting point, rather than as a definitive, final text.
Article X
in the register and language of existing treaties
-
Artificial Intelligence in Nuclear Command, Control and Communications
Definitions (for the purposes of this Article)
"Artificial intelligence system" means any machine-based system that, given a set of objectives, is capable of generating outputs such as predictions, recommendations, decisions, or content that influence real or virtual environments.
"Nuclear command, control and communications system" (NC3) means any system, network, or infrastructure used by a nuclear-weapon State to authorise, transmit, or execute decisions relating to nuclear forces, including early-warning, targeting, and launch systems.
"Meaningful human control" means a condition in which an identified, accountable human decision-maker retains deliberate authority over any action that could constitute or trigger the use of nuclear weapons, with sufficient time, information, and legal authority to exercise such control.
Article X: Text
X.1. Each nuclear-weapon State Party undertakes that no artificial intelligence system shall be empowered to authorise, initiate, or execute the launch or use of nuclear weapons, or to remove or override a safeguard against such launch or use, without the direct and prior decision of an identified human decision-maker exercising meaningful human control.
X. 2. Each nuclear-weapon State Party undertakes to ensure that any artificial intelligence system integrated into its NC3 infrastructure is subject to documented procedures that preserve the principle in paragraph 1, and shall provide to the International Atomic Energy Agency, on a periodic basis not exceeding three years, a written assurance of compliance with this paragraph.
X. 3. State Parties undertake not to transfer to any non-nuclear-weapon State, or to any non-State entity, any artificial intelligence system specifically designed or adapted for integration into nuclear command, control, and communications infrastructure.
X. 4. State Parties shall consult within the framework of the Review Conference process, no less than once every five years, on emerging risks to strategic stability arising from the integration of artificial intelligence in military and nuclear systems, with a view to agreeing supplementary confidence-building measures.
X. 5. Nothing in this Article shall be construed as limiting the use of automated systems for routine administrative, logistical, or non-decisional functions within NC3 infrastructure, provided such systems do not bear upon the authority to authorise or execute nuclear use.
-
Artificial Intelligence in Biological Research with Weapons-Relevant Applications
Definitions (for the purposes of this Article)
"AI-enabled biological design tool" means any artificial intelligence system capable of predicting, generating, or optimising biological sequences, protein structures, or pathogen characteristics, including but not limited to protein-structure prediction systems, de novo protein design systems, and genomic language models.
"Weapons-relevant application" means any application of such a tool directed toward enhancing the transmissibility, lethality, immune evasion, or environmental persistence of an agent that falls within the scope of Article I of this Convention.
Article X: Text
X.1. Each State Party undertakes never in any circumstances to develop, produce, acquire, or retain any artificial intelligence system whose design purpose or demonstrated application is to facilitate the development of biological or toxin weapons as defined under Article I of this Convention.
X.2. Each State Party undertakes to establish and maintain national oversight measures applicable to AI-enabled biological design tools operated within its jurisdiction or under its control, including mechanisms to detect and prevent weapons-relevant applications of such tools, whether by State entities, academic institutions, or private actors.
X.3. State Parties shall not transfer to any recipient any AI-enabled biological design tool where there is credible reason to believe such tool would be applied to weapons-relevant purposes. Each State Party shall enact national export control legislation giving effect to this obligation.
X.4. State Parties shall submit to the annual Confidence-Building Measures process a declaration identifying:
(a) the categories of AI-enabled biological design tools operated within their jurisdiction;
(b) the national oversight mechanisms in place pursuant to paragraph 2; and
(c) any detected or suspected incidents of misuse, consistent with national security requirements.
X.5. State Parties undertake to share, through the Implementation Support Unit, best practices and technical guidance on biosecurity measures applicable to AI-enabled biological design tools, with particular regard to access controls, output monitoring, and dual-use risk assessment frameworks.
X. 6. Nothing in this Article shall be interpreted as restricting the legitimate peaceful application of AI to medicine, public health, agricultural science, or environmental research, or as limiting access by developing States to AI technologies for beneficial biological purposes in accordance with Article X of this Convention.
-
PROTOCOL VI: Protocol on Autonomous Weapon Systems
Definitions (for the purposes of this Protocol)
"Autonomous weapon system" (AWS) means a weapon system that, once activated, can select and engage targets without further human intervention for each individual engagement.
"Meaningful human control" means a condition in which a human operator, with appropriate time, situational awareness, and authority, takes the decision to use force against each individual target or class of targets, and bears legal accountability for that decision.
"Critical functions" means the functions of acquiring, tracking, selecting, and attacking targets.
Protocol VI:
Prohibition on fully autonomous lethal targeting. High Contracting Parties undertake to prohibit and prevent the development, production, transfer, and use of any weapon system in which critical functions operate without meaningful human control as defined in this Protocol.
Obligation to review. Each High Contracting Party shall establish a national legal review process, in accordance with Article 36 of Additional Protocol I to the Geneva Conventions, applicable to any weapon system incorporating autonomous functions in the exercise of critical functions prior to its procurement, development, or deployment.
Accountability. High Contracting Parties shall ensure that a legally identifiable human commander or operator is accountable for any use of force by a weapon system covered by this Protocol, and that existing frameworks of command responsibility under international humanitarian law apply without diminution.
Non-State Parties. High Contracting Parties undertake to make every effort to ensure that non-State armed groups operating within their territory or under their effective control do not acquire or use weapon systems prohibited under paragraph 1.
Review Conference. A Review Conference shall be convened not later than five years after the entry into force of this Protocol to assess its implementation and consider whether further measures are required.
Savings clause. Nothing in this Protocol prohibits weapon systems that retain a human in command over targeting decisions, automated defensive systems operating within clearly defined and geographically bounded parameters against incoming munitions, or systems used for non-lethal purposes.
-
Artificial Intelligence in Chemical Weapons-Related Research and Delivery
Definitions (for the purposes of this Article)
"AI-assisted chemical design" means the use of any artificial intelligence system to predict, model, or optimise the synthesis, structural modification, or toxicological properties of chemical compounds in a manner with potential application to weapons prohibited under this Convention.
"Autonomous dispersal system" means any system using AI to autonomously select, time, or geographically target the release of a toxic chemical without direct human control of each individual release event.
Article X: Text
X.1. Each State Party undertakes never in any circumstances to use artificial intelligence to design, optimise, or characterise any chemical that would, if produced, constitute a chemical weapon as defined under Article II of this Convention, or to develop or deploy any autonomous dispersal system for the delivery of toxic chemicals for hostile purposes.
X.2. The OPCW Technical Secretariat is mandated to maintain a standing scientific advisory panel on AI and chemical security, tasked with reviewing developments in AI-assisted chemical design and providing recommendations to the Conference of State Parties on whether additional compounds, compound classes, or design methodologies should be subject to the Schedule and verification regime.
X.3. State Parties that operate facilities conducting AI-assisted chemical research shall include in their annual declarations, submitted pursuant to Part VII of the Verification Annex, a description of the AI systems and large-scale computational tools used in chemical research, together with the safeguards in place to prevent application to prohibited purposes.
X.4. The Technical Secretariat may, following approval by the Executive Council, include the review of AI-assisted chemical research capabilities within the scope of routine industry inspections carried out pursuant to Article VI and Part IX of the Verification Annex.
X.5. State Parties shall cooperate to develop and share, through the OPCW, model national legislation and best practices for the governance of AI tools with potential dual-use application to chemical weapons development, in accordance with the principles of Article XI on economic and technological development.
-
SUPPLEMENTARY PROTOCOL III: Controls on the Transfer of Artificial Intelligence Systems for Military and Security Applications
Definitions (for the purposes of this Protocol)
"Controlled AI system" means any artificial intelligence system, including its model weights, training data, and inference infrastructure, that has primary utility for autonomous targeting, mass surveillance, autonomous cyber-offensive operations, or the development of weapons listed on the Munitions List or Dual-Use List.
"Transfer" means any conveyance of a controlled AI system to a recipient outside the originating Participating State, whether by physical delivery, electronic transmission, cloud access provisioning, API access, or any other means of making the system available for use.
Article X: The Text
X.1. Participating States shall apply export licensing requirements to all transfers of controlled AI systems, as defined in this Protocol, regardless of the medium or modality of transfer. The granting of remote access, API access, or cloud computing services constituting a transfer of a controlled AI system shall be treated as an export for the purposes of national licensing requirements.
X.2. The Wassenaar Secretariat shall maintain and update, on an annual basis, a Controlled AI Systems List specifying categories of AI system subject to control under this Protocol. The List shall be developed by a standing Technical Expert Group on AI Systems, whose recommendations shall be adopted by a qualified majority of Participating States rather than by consensus.
X.3. Participating States undertake to deny transfer licences where there is a credible risk that the recipient will use the controlled AI system for:
(a) serious violations of international human rights law, including the conduct of mass surveillance, persecution, or suppression of political dissent;
(b) autonomous lethal operations without meaningful human control; or
(c) the development of weapons of mass destruction.
X. 4. Participating States shall submit annual reports to the Secretariat documenting licensed and refused transfers of controlled AI systems, disaggregated by destination, system category, and stated end-use. These reports shall be shared among Participating States in full, and an aggregated summary shall be published publicly.
X. 5. This Protocol shall enter into force for each Participating State upon signature and shall not be subject to the consensus amendment procedure of the Wassenaar Initial Elements. Amendments to this Protocol shall require a two-thirds majority of Participating States.
-
Artificial Intelligence Systems in Outer Space
Definitions (for the purposes of this Article)
"Autonomous space weapon system" means any object placed in outer space that incorporates an artificial intelligence system capable of selecting and engaging, neutralising, or destroying space objects or surface targets without real-time human authorisation of each individual engagement.
"AI-enabled space surveillance system" means any space-based artificial intelligence system designed to collect, process, and disseminate geospatial intelligence about individuals, populations, or facilities on Earth's surface, in a manner not subject to the oversight provisions of this Treaty.
Article X: The Text
X.1. States Parties undertake not to place in orbit around the Earth, install on the Moon or any other celestial body, or station in outer space, any autonomous space weapon system as defined in this Article.
X.2. States Parties undertake that any artificial intelligence system aboard a spacecraft or space object capable of physically interfering with another state's space object, or of directing force against surface targets, shall be subject to real-time human authorisation requirements consistent with the principle of meaningful human control, and shall not operate in autonomous lethal mode.
X.3. States Parties shall, through the United Nations Committee on the Peaceful Uses of Outer Space (COPUOS) and the UN Office for Outer Space Affairs, register the presence of any AI system aboard a space object that performs functions covered by paragraph 2, in addition to the information required under the Registration Convention.
X.4. States Parties shall enter into consultations within ninety days upon receiving a notification from another State Party expressing concern that an orbital AI system operated by the first State Party may be inconsistent with this Article, in accordance with the consultation procedure established under Article IX of this Treaty.
X. 5. States Parties recognise that AI-enabled space surveillance systems directed at civilian populations without adequate legal oversight may constitute a form of hostile act contrary to the principles of this Treaty and the UN Charter, and undertake to negotiate, through COPUOS, transparency measures applicable to such systems.
-
Prohibition on Artificial Intelligence in Nuclear Weapons Systems and Related Infrastructure
Each State Party undertakes never under any circumstances to develop, deploy, or operate any artificial intelligence system that is integrated into a nuclear weapons system and that bears upon the decision to arm, target, or use a nuclear weapon, or to take any action that removes, overrides, or circumvents a human safeguard against nuclear use.
Each State Party undertakes to prohibit and prevent within its jurisdiction and control any activity by State entities, private entities, or individuals that would involve the design, development, production, testing, stockpiling, or transfer of AI systems whose purpose is the automation of nuclear weapons functions as described in paragraph 1.
Each State Party shall, in implementing Articles 6 and 7 of this Treaty on victim assistance and environmental remediation, give due consideration to harms arising from the use of automated or AI-assisted systems in the conduct of nuclear testing or the management of nuclear materials, and shall include assessments thereof in its national implementation reports.
The Meeting of States Parties shall, at each session, include on its agenda a standing item on emerging risks from the integration of artificial intelligence in nuclear and related systems, with a view to strengthening the normative framework of this Treaty and contributing to its universalisation.
State Parties that engage in diplomatic dialogue with nuclear-armed States not party to this Treaty shall include, as part of such dialogue, efforts to promote the principles of paragraph 1 as a matter of customary international norm, and shall report such efforts to the Secretariat.
This Article shall be read consistently with the humanitarian principles underpinning this Treaty: no technological system — however sophisticated — shall be permitted to diminish the irreducible human responsibility for decisions that could result in the use of nuclear weapons, and the catastrophic, indiscriminate, and persistent humanitarian consequences that such use entails.
-
Artificial Intelligence and the Gendered Conduct and Consequences of Armed Conflict
Definitions (for the purposes of this Article)
"Gender-disaggregated impact data" means data on the effects of a weapon system or military operation broken down by gender, sufficient to reveal differential harms.
"AI-assisted conflict-related sexual violence risk" means the use of, or failure to account for, artificial intelligence systems — including surveillance, targeting, or pattern-of-life analysis tools — in ways that create, increase, or fail to mitigate the risk of conflict-related sexual and gender-based violence.
"Meaningful participation" means the substantive inclusion of women and women-led civil society organizations, including from affected communities, in the design, oversight, and review of military AI systems and their governing frameworks — not consultation after deployment decisions have already been made.
Article X: Text
X.1. Member States and parties to armed conflict undertake to ensure that any artificial intelligence system used for surveillance, targeting, or pattern-of-life analysis in the conduct of hostilities is assessed, prior to deployment, for its potential to increase the risk of conflict-related sexual and gender-based violence, including through the misidentification of civilians, the profiling of households, or the disclosure of information that could expose individuals to gendered harm.
X.2. Member States undertake to collect and make publicly available, on an annual basis, gender-disaggregated impact data concerning the use of AI-enabled weapons and surveillance systems in armed conflict, including data on civilian casualties, displacement, and conflict-related sexual violence attributable in whole or in part to AI-assisted operations.
X.3. Member States undertake to ensure the meaningful participation of women, including from conflict-affected communities, in the design, procurement review, and oversight bodies governing military artificial intelligence systems, and shall report on the composition of such bodies through existing Women, Peace and Security reporting mechanisms.
X.4. No artificial intelligence system shall be deployed in a manner that treats gender as a targeting variable, whether directly or through proxy indicators correlated with gender, except where the sole purpose is to reduce harm to a protected group.
X.5. Member States shall ensure that reparations, victim assistance, and post-conflict accountability mechanisms established under this Agenda explicitly account for harms arising from AI-assisted military operations, including psychological, economic, and reproductive harms disproportionately borne by women and girls, and shall not treat the automated nature of a harm as diminishing a State's responsibility to provide remedy.
X.6. The Security Council shall include, as a standing item in its periodic open debates on Women, Peace and Security, a review of emerging risks and reported harms arising from the military use of artificial intelligence, with a view to strengthening this Agenda's implementation at the pace of the technologies it seeks to govern.
a people’s mirror of article X
-
We who have waited for the warning to be wrong
We are the ones who do not get a briefing when the system is uncertain. We will not be consulted in the ninety seconds a machine is given to decide whether one sensor's truth is enough. States write, again, of "meaningful human control" — meaningful to whom, controlled by which human, reachable in how many seconds?
We do not ask for a written assurance filed once every three years. We ask that no algorithm be permitted to shorten the time a human being has to doubt what a machine tells them. We ask that the right to hesitate — to say I am not sure, wait one more minute — be written into law as a right belonging to us, who cannot hesitate on our own behalf once the decision is made. The record of near-catastrophe is a record of humans who doubted, not machines that verified. We ask for a treaty that protects doubt.
-
We who would be the outbreak's first page
We are not consulted when a design tool decides which protein to try next. We do not sit on the national oversight measures that watch over research we will never read about until it appears in an outbreak report. We are downstream of every guess a model makes about transmissibility, and upstream of nothing.
The drafters write of "credible reason to believe" before a transfer is refused, of declarations submitted once a year describing categories of tools in use. We ask: credible to whom, and refused before or after the sequence is already designed, already run, already loose? We do not want annual declarations describing categories. We want to know, in something closer to real time, what has been generated that did not exist in nature the day before, and who decided it was safe enough to leave the lab. We ask for a treaty that treats a novel pathogen the way it treats a warhead: something that cannot un-exist once built, and so must never be allowed to reach the point of being built.
-
We who are recognized by a camera, not by a name
We are the pattern a sensor is trained to recognize: a gait, a heat signature, a rooftop at a certain hour. We are not consulted on the dataset that decided what a "combatant" looks like from above. We do not get to appeal a classification before it becomes a targeting decision. We do not learn whether we were correctly or incorrectly identified — only, afterward, whether we are alive.
The drafters write of "meaningful human control," "critical functions," a "legally identifiable commander." Identifiable to whom, on what timeline, with what remedy for us — the misidentified, the ones the system decided we were? We do not want a national legal review filed before deployment. We want a name for every person a system decides to treat as a target, and a human being, reachable by someone who speaks for us, accountable in a way we can act on — not a chain of command that ends in an inquiry we will never see.
-
We who breathe what was optimized
We are not in the room when a model is asked to optimize a molecule's toxicity, its persistence, its resistance to countermeasures. We learn about a scientific advisory panel's recommendations only after the Conference of State Parties has acted on them, if it acts at all. We are the ones an autonomous dispersal system is built to reach without a human choosing, each time, to release it.
The drafters write of "routine industry inspections" that may include AI-assisted chemical research, subject to Executive Council approval. May. We ask for must. We do not want a declaration listing the tools in use at a facility, filed once a year to a Secretariat. We want the right to know, before the fact, what a facility's models are being trained to find — and a floor, not a schedule that can always be expanded to permit one more compound.
-
We who are the end-use
We are the "recipient" in the licensing form, except we are never named — only the government that receives the system is named, and it is often the same government the system will be turned against us. We do not see the Controlled AI Systems List before it is updated. We get no vote on the Technical Expert Group that decides what counts as "primary utility for autonomous targeting" this year.
The drafters write that a licence shall be denied where there is "credible risk" that we, specifically, will be surveilled or targeted without meaningful human control. We ask who assesses credibility, and whether our testimony counts toward it, or only a government's assurances do. We do not want an aggregated summary published once a year, after the systems are already deployed against us. We want the list of what was sold, to whom, published before the sale — so that we, the end-use, have a chance to object while it might still matter.
-
We who are watched from above and cannot watch back
We cannot see the satellite that watches us the way it can see us. We are not registered with COPUOS; only the system trained on our "pattern of life" is registered, and even then, only if it performs a function the treaty happens to define. A State Party gets ninety days to consult another State Party about a concern — we get no days, and no standing, to consult about a concern of our own.
The drafters write of transparency measures to be "negotiated," someday, through COPUOS, for surveillance systems "directed at civilian populations without adequate legal oversight." We ask: how many years of being watched constitute someday? We do not want a consultation procedure between states who may or may not act on it. We want to know we are being watched, by whom, and why — before the file on us is already built.
-
We who are the humanitarian consequence, not the agenda item
We are the ones this Treaty exists for — its victim assistance and environmental remediation provisions were written because of us, survivors of testing, descendants of contamination. And still, an Article X drafted in our name asks only that States Parties "give due consideration" to harms from automated systems in implementing obligations meant to reach us directly.
We do not want due consideration. We want the same irreducible human responsibility the drafters name in their own closing clause — "no technological system shall be permitted to diminish" it — extended to us: no automated system shall be permitted to diminish the responsibility a State owes us for what its testing, its production, its now-automated nuclear infrastructure, has already done and may yet do. We are not a standing agenda item to be revisited at each Meeting of States Parties. We are why the meeting exists.
-
We who were never the subject of the sentence
Every treaty in this archive speaks of "combatants," "commanders," "state parties" — categories never built with us in mind, erasing us twice: once when the violence reaches us anyway, though we were never its intended subject, and again when the accounting afterward does not ask what happened to us in particular.
We are the households an algorithm marks as a "pattern of life" worth watching. We are the women who carry the displacement, the sexual violence, the loss of livelihood that follow an AI-assisted strike — none of which appears in any declaration to any review conference, because no review conference asks. We are the ones who negotiated the peace after the men who built the weapons had gone home. We do not want a savings clause protecting "legitimate application." We want disaggregated data, because the aggregate hides us. We want a seat, not a subclause.