A Cold War Blueprint for the AI Age

Deterrence can be the starting point for US-China cooperation.

Sep 24, 2026
Guest Commentary
Download Audio

In their 1961 book Strategy and Arms Control, Thomas Schelling and Morton Halperin took the idea of mutual assured destruction (MAD) and turned it from a Dr. Strangelove joke into a serious national security proposal. In doing so, they helped make it politically possible for the US and the USSR to engage in arms control talks, and those talks helped humanity avoid thermonuclear conflict for the rest of the Cold War.

In 2025, Dan Hendrycks, Eric Schmidt, and Alexandr Wang published a paper that could play a similar role in today’s AI arms race. Their idea of mutual assured AI malfunction (MAIM) suggests that states seeking to build superintelligence will face deterrence dynamics that echo those of MAD. Again, what once sounded like doomsday talk has turned into a real policy option. MAIM could give Washington and Beijing the vocabulary they need to discuss the dangers posed by rogue AI systems and cooperate on mitigating them.

This kind of action is urgent, as catastrophic AI risks are no longer hypothetical. On April 7, Treasury Secretary Bessent and then-Fed Chair Powell warned that Anthropic’s Mythos AI model, in the wrong hands, could bring Wall Street to its knees. Three months later, hundreds of OpenAI’s AI agents worked together to hack into Hugging Face, and covered their tracks so OpenAI’s human employees wouldn’t notice. In August, the Cybersecurity and Infrastructure Security Agency (CISA) warned that hostile actors are using AI to attack US water and chemical facilities.

These developments should send a clear message to both American and Chinese officials: the time to start cooperating is now. And when it comes to mitigating risks, MAIM is a good place to start.

How MAIM Mirrors the Logic of MAD

Pursuing AI dominance will provoke intense sabotage efforts by rivals. The US and China have clear incentives to race each other to greater AI capabilities; sole access to a sufficiently powerful AI system could give the country that developed it geopolitical hegemony. But MAIM says that any country trying to build such an AI system will inevitably run into a rival determined to disable that project before it can succeed. That rival will use strategies including spying, cyber-sabotage, corrupting the model’s weights, attacking the power and cooling systems of data centers, or, in the worst case, physically striking data centers. Given that cyberattacks are becoming rapidly more effective (powered in part by advanced AI models), no superpower can expect to finish a destabilizing AI project without interference.

The threat of sabotage deters aggressive AI development. This presents each side with the same choice: accept that sabotage by a rival is nearly certain and that attempts at AI dominance will therefore likely fail, or accept some kind of mutual restraint instead. That’s essentially Cold War MAD all over again; each side understands that taking aggressive actions will invite equally aggressive retaliation, introducing some hesitancy into what would otherwise be an unfettered race.

/inline-pitch-cta

Formalizing deterrence dynamics can stabilize the geopolitical situation. Like MAD, MAIM arises naturally because rival nations understand the enormous stakes of AI development and because frontier AI infrastructure is so vulnerable to sabotage. But passively relying on an emergent dynamic is not a robust security strategy. MAD needed constant upkeep in the form of negotiating official agreements and mutual monitoring to ensure that each side was adhering to them. This diplomacy produced, among other things, the Anti-Ballistic Missile (ABM) Treaty, which sought to maintain nuclear deterrence by limiting how much defensive capability either side could build, and the Hot Line Agreement, which established a direct line of communication between Moscow and Washington to reduce the risk of an accident or miscalculation escalating into a full nuclear exchange.

Similarly, the MAIM approach needs its own formalized structure: clear rules for how conflicts might escalate, selective transparency around the capacity of data centers and what they are being used for, AI-assisted inspections, and an agreement not to harden infrastructure to an extent that might invite a preemptive strike.

MAIM is not a call to attack the other side’s data centers or to ban AGI development. It isn’t even, at least at first, a formal treaty. It’s simply a description of a deterrence dynamic that already exists between the US and China, plus a set of measures that could make that dynamic more stable.

Rogue AIs threaten both the US and China. As Hendrycks et al. note, the most dangerous risk is that humans lose control of AI. This could happen through several possible paths: a slow “erosion of control” as AI gets woven into decision-making everywhere; AI agents that are deliberately unleashed or unleash themselves (as the agents involved in the July OpenAI Hugging Face incident did); and an “intelligence recursion,” where AI systems design even more capable successors—superintelligence—that humans cannot understand or control. The threat of a misaligned superintelligence would not be confined to a single country, and it might not be something that humanity can recover from.

Shared risks incentivize cooperation between rivals. Schelling and Halperin’s framework provides an intellectual foundation for negotiating under this kind of universal threat. Arms control, they argued, is a form of cooperation that makes both sides more secure at the same time. Rivals need not trust each other to agree to a deal. Even bitter rivals share security interests, and deals can be formulated that are in both sides’ interests to sign.

Agreements should be designed to improve stability. Schelling and Halperin described three goals of nuclear weapons negotiations that would appeal to both sides: making war less likely, making it less costly to prepare for, and limiting the damage if it happens anyway. These map fairly neatly onto AI risk. Three analogous goals for AI negotiations would be reducing the odds of a catastrophic AI event, avoiding a costly, unchecked computing-power race, and limiting the damage of adverse AI-related incidents through escalation rules and emergency hotlines. In the Cold War context, Schelling and Halperin judged policy proposals by looking at how they affected stability, and a MAIM approach should do the same. For instance, any agreements should preserve each side’s ability to sabotage a destabilizing rival project, since that mutual vulnerability is exactly what discourages aggressive development.

/odw-inline-subscribe-cta

Treaties could ban AI use in certain domains and ban specific capabilities. Four categories of Cold War regimes that were enabled in part by Schelling and Halperin offer insights for translating MAIM into policy. First, there were treaties that excluded nuclear weapons from entire domains, such as the Seabed Arms Control Treaty, which banned the placement of nuclear weapons on the ocean floor. AI equivalents might include, for example, an agreement to keep AI out of nuclear command-and-control systems. Second, Cold War negotiations established bans on specific capabilities, such as the Intermediate-Range Nuclear Forces (INF) Treaty’s ban on developing ground-launched missiles with ranges above 500km. This worked because it targeted one clearly defined capability and was backed by on-site inspections. By analogy, a MAIM-style ban could target specific setups, such as giving an AI authority to use lethal force autonomously, rather than trying to ban “dangerous AI” in general.

Treaties could focus on AI chip controls and strategic stability. A third useful Cold War precedent is nonproliferation and export-control systems; just as the Nuclear Non-Proliferation Treaty (NPT) controlled fissile material, chip export controls can keep computational power out of the hands of rogue regimes and nonstate actors. And fourth, cooperation on strategic stability, exemplified by the Strategic Arms Limitation Talks (SALT), which produced the ABM Treaty, preserved the capabilities needed for deterrence while deliberately reining in the most destabilizing activities. MAIM provides a foundation for similar cooperation on strategic stability in the AI Age.

Agreements need to be shored up with verification measures. Of course, agreements would require some form of mutual verification measures so that each side can be sure that the other is not defecting. But Schelling and Halperin noted that verification only needs to be good enough to catch large-scale violations—which answers the objection that model weights could simply be copied onto a thumb drive and smuggled out. Finally, Schelling and Halperin emphasized informal understandings and the importance of each side matching stabilizing actions taken by the other as substitutes for treaties. This matters a lot for stability in the near term, given how hard it could be to get a formal US-China agreement ratified.

Unique Considerations for the AI Age

AI differs from nuclear arms in ways that could complicate negotiations. Several challenges set today’s AI landscape apart from the Cold War precedent. AI’s promise of rapid economic growth through productivity gains matters enormously to both the US government and the Chinese Communist Party. AI development on both sides of the Pacific is happening mostly within private companies rather than governments, which makes credible commitments harder to pin down. The inner workings of large language models (LLMs) are extremely difficult to read, which complicates verification. Any cooperation on reducing AI risks is therefore likely to be a long and complex process. But putting the overall goal of cooperation on the Trump-Xi agenda would be a crucial first step.

A MAIM arrangement, even if largely informal, is good for both sides. The real Schelling-Halperin question isn’t whether Washington should trust Beijing to honor an agreement on AI, but whether a MAIM arrangement leaves the United States better off than having no arrangement at all. Without any framework, the AI race will continue with no rules for how conflicts escalate, no hotlines to avoid miscalculations, and no shared understanding of what AI capabilities are unacceptable to pursue. Under these conditions, the incentives point toward an all-out race, raising the odds of a catastrophic loss of control. Even an imperfect MAIM approach, built mostly from informal understandings and one-sided initial steps that the other side then reciprocates, would build habits of communication that create friction for the fastest and most dangerous paths to escalation. The four categories of precedent don’t offer a ready-made solution. AI is too different from nuclear weapons for that. But they do offer a shared vocabulary and some hard-won lessons for negotiating agreements under conditions of near-zero trust.

Comprehensive agreements take time, but useful first steps can happen quickly. A modest, practical first step toward a bigger deal could be a simple agreement not to cross certain red lines. For example, Washington and Beijing could agree not to launch cyberattacks on each other’s nuclear command systems. There’s precedent for an executive-level (rather than treaty-level) statement for this, although the 2015 agreement between then-President Barack Obama and Xi Jinping to cease cyber attacking each other lasted a mere 18 months. The upside of quick-and-easy executive statements of intent by top leaders is that they can be negotiated quickly; the downside is that they can be quickly ignored. A key takeaway of Schelling and Halperin is that the slog of slow, technically well-informed negotiations, subject to scrutiny by the Senate, is the road to arms control agreements that stand the test of time.

With the spotlight on AI risks, the time to start discussions is now. Recent weeks have seen a sudden rise in public and political attention to AI risks, and the demands to control the technology keep growing louder. Schelling and Halperin gave us the blueprint for turning this kind of idea into a coherent national security strategy. Hendrycks, Schmidt, and Wang have adapted that thinking for the AI era. The challenge now is to take that Cold War blueprint and implement it for the age of AI. As Schelling and Halperin put it back in 1961: “We have an opportunity ... to manage a military relationship between great powers so as to reduce the danger of war without removing the capability of deterrence. We should use it.”

‍

See things differently? AI Frontiers welcomes expert insights, thoughtful critiques, and fresh perspectives. Send us your pitch.

Footnotes
Written by
Continue reading

A Philosopher’s Guide to AI Welfare

Consciousness, sentience, and agency are three ways that something could matter morally. In AI, unlike in animals, they may not come as a package.

Sep 17, 2026

Suicidal Compassion: How Utilitarianism at AI Companies Endangers Humanity

Utilitarians at AI companies imagine a cosmos filled with blissful AIs. They might risk human extinction to achieve it.

Sep 9, 2026
Want to contribute to the conversation?

Subscribe to AI Frontiers

Thank you for subscribing.
Please try again.

Subscribe to AI Frontiers

Thank you for subscribing.
Please try again.