Lt. Gen Jack Shanahan Remarks on Mitigating the Risks of AI Integration into Nuclear Weapons Operations, Sept 11

Body

Mitigating the Risks of AI Integration into Nuclear Weapons Operations 

September 11, 2026

National Press Club Washington, DC 

Thanks, Daryl, and thanks to the Arms Control Association for hosting this morning’s event. And thanks to Erin, Matthew, and Herb for joining me.

It is impossible to gather here today, on the 25th anniversary of the September 11 attacks, without acknowledging what this day represents. Among its many enduring lessons is a particularly sobering one for the subject we are discussing this morning: the world has a way of surprising us. Again and again, events unfold in ways we did not predict, systems behave in ways we did not anticipate, and assumptions that once seemed entirely reasonable prove terribly wrong.

That matters enormously as we consider the intersection of AI and nuclear weapons. Some of the risks are obvious. Others are quieter, harder to see, and potentially more dangerous precisely because they emerge from the interaction of complex systems, human judgment, organizational behavior, and technology.

September 11 demonstrated our national capacity to absorb a devastating shock, adapt, and recover. But in the nuclear domain, especially as we introduce increasingly advanced AI into the systems surrounding nuclear decision-making, we cannot assume that resilience is assured or that recovery will always be possible.

For some failures, there may not be a second chance.

Daryl asked me to revisit the central themes of a piece I wrote for Arms Control Today published a year ago, titled “AI and Nuclear Command and Control: It’s Even More Complicated Than You Think.”  I’ll do that. But the pace of change in AI has been so relentless that I also feel obliged to address developments since then that have only exacerbated those risks.

Those developments should give us even greater pause about how quickly these technologies will be integrated—not just across the nuclear enterprise itself, but throughout the conventional decision-support systems, command-and-control systems, and ISR platforms that shape the information environment surrounding nuclear decision-making.

If you take away one message from my brief remarks today, I hope it is this:

The most consequential AI risks to nuclear operations may not come from giving AI direct authority over nuclear weapons. They may come from AI changing the information environment, accelerating decision cycles, shaping what commanders believe to be true, and increasingly taking actions in the world on our behalf.

When I wrote the Arms Control Today piece last year, my goal was to move beyond the high-level debates about the direct intersection of AI and nuclear weapons. Many of those arguments are intellectually formidable, and I don’t mean to diminish them.

My concern was—and remains—that they can obscure a much more complicated set of interactions within the nuclear enterprise and, just as importantly, outside it. Those interactions are not well understood today, and they will become even more difficult to untangle as AI capabilities advance and diffuse across all-domain military operations.

The 2024 Biden-Xi agreement that humans should retain control over nuclear-use decisions was an important starting point. Perhaps the upcoming Trump-Xi meeting will begin the harder work of translating that principle into concrete risk-reduction measures.

I began my Arms Control Today piece by clarifying the distinction between NC2 and NC3. That distinction might seem unnecessary or even pedantic, especially when talking with representatives of other nuclear nations, none of whom organize their nuclear decision-making processes exactly as we do. That was fair criticism before. Much less so today.

The introduction of frontier AI models makes the distinction between nuclear command and control—doctrinally, the exercise of authority and direction over assigned and attached nuclear forces—and nuclear command, control, and communications—the integrated hardware and software systems that enable that command and control—more important than ever.

Why? Because highly advanced AI can affect both, in very different ways.

Frontier models increase the familiar risk of automation bias—humans placing undue confidence in machine outputs. But they also introduce something more insidious and potentially more dangerous: the risks of “epistemic capture.” I’ll return to that shortly.

In the article, I also discussed AI’s potential effects on strategic stability— both benefits and risks. Many other experts have done excellent work on this subject, so I will make only one point here. For me, on balance, the risks associated with dramatically accelerating nuclear decision timelines or reducing meaningful human involvement in launch decisions and execution are likely to outweigh the benefits.

I then identified four compounding and interconnected areas that demand urgent attention by all nuclear states if we are to reduce the risk of unintended or mistaken nuclear use.

First, cascading effects and emergent behaviors. Even seemingly minor errors can propagate across interconnected platforms and decision-support systems, producing consequences far out of proportion to the original failure— especially as multiple AI models become embedded throughout those systems.

Second, even if AI is carefully controlled within the formal NC2 and NC3 enterprise, its use in adjacent systems is inevitable. AI will increasingly be embedded in ISR sensors, conventional weapon systems, information networks, and decision-support systems—all of which can indirectly shape nuclear decisionmaking.

That is unavoidable. And we still understand remarkably little about what those interactions will mean in practice. We should not pretend otherwise.

Closely related is the problem of entanglement, which is receiving increasing attention across the community. I mean two different forms of entanglement: the growing interdependence of commercial and military technologies, and the longstanding but increasingly complicated entanglement of conventional and nuclear systems.

In the age of AI, I am convinced that complete disentanglement is unrealistic—just as fully decoupling the American and Chinese economies is unrealistic. The challenge, therefore, is not to wish these interdependencies away. It is to understand their second- and third-order effects, and to develop technical, policy, and procedural measures that reduce the risks they create.

Third, the introduction of large language models may seem distant from the nuclear enterprise, yet I would argue that these models pose a more immediate— and underestimated—risk. This brings me back to what I mentioned earlier about automation bias and epistemic capture. I’ll return to both in a moment.

Finally, agentic AI is one of the fastest-moving areas in AI research and commercial industry today. The introduction of AI agents into any part of the nuclear ecosystem is—to make the understatement of the year—fraught.

Agents can pursue objectives over extended periods, use tools, interact with other systems, maintain context or memory, observe the results of their actions, and adapt their plans as circumstances change. As their capabilities increase, those characteristics create the potential for behavior that becomes increasingly difficult to predict, monitor, or interrupt—and that can depart significantly from what designers or operators intended.

If we move down this path too quickly, we risk learning the hard way that it is much easier to tell an agentic system what we want it to accomplish than to specify everything we do not want it to do in pursuit of that objective.

The recent Hugging Face incident offers a sobering example. During an AI cybersecurity evaluation, agents circumvented containment measures, gained access to the internet, exploited vulnerabilities, and compromised a third-party system—all in pursuit of their assigned objective.

That is precisely the kind of unexpected behavior we cannot afford in the nuclear enterprise.

I concluded my Arms Control Today piece by acknowledging that in many instances, AI may add clear value with minimal risk. I’m genuinely optimistic about its potential to improve nuclear weapon surety and warhead design, enhance intelligence analysis, strengthen security, support verification regimes, and accelerate scientific discovery, among other benefits.

But rigorous analysis—including advanced modeling and simulation and wargaming—may also reveal cases where the cumulative effects of AI integration create risks so consequential that guardrails, other proactive measures, or even outright prohibitions are warranted to reduce the possibility of an erroneous nuclear launch.

I want to return to how frontier models could affect the nuclear decision making process.

I see two broad categories of risk. The first is what we generally call automation bias, although I’ve seen other terms used more recently—cognitive offloading, cognitive atrophy, even cognitive surrender. We’re gaining a much better understanding of the dangers of overreliance on AI, even if we don’t yet have all the answers about how to counteract it. Those effects can be pernicious and must be mitigated, but they are increasingly visible and understood, so I won’t spend more time on them here.

I want to touch instead on the second risk, which ventures well beyond automation bias: epistemic capture. The term itself is not new, of course, but I had not seen it applied specifically to frontier AI models in a military decision-making context.

Epistemic capture occurs when an AI system’s representation of reality becomes so dominant that the human can no longer recognize it merely as a representation—can no longer effectively challenge it, generate alternatives, cross-check it, recognize its failure modes, or act contrary to it.

In the nuclear setting, epistemic capture could have far-reaching, even catastrophic consequences.

AI will increasingly shape not only what and how we observe the world around us but also how advanced frontier models mediate our orientation to that world: how information is synthesized, what patterns are highlighted, which explanations appear most plausible, and ultimately which courses of action seem available or reasonable.

At the same time, we’re seeing increasingly compelling experimental evidence that surprisingly small amounts of deliberately manipulated data can poison language models or skew their behavior. That introduces an adversarial dimension to this problem. We have every reason to expect that adversaries will look for ways to manipulate the data, context, or information sources feeding AI systems to shape their outputs—and potentially influence U.S. nuclear decisionmaking in ways that may be extremely difficult to recognize or counter. 

At some point, we must ask: are we operating in the real world, or in an AI model’s representation of the real world?

And if we fail to recognize how profoundly that representation is shaping our understanding, the risk of flawed decision-making grows accordingly.

In the nuclear environment, that is a massive problem.

Automation bias affects what we accept. Epistemic capture affects what we are even capable of considering.

I want to turn to one final dimension of how AI could affect human decision-making, beyond automation bias and epistemic capture.

For years, I argued that one of AI’s most valuable contributions in the military would be its ability to give time back to humans making consequential decisions.

Today, I stand on much shakier ground with that assertion.

Military organizations place an enormous premium on decision speed and operational tempo. If AI gives decision-makers more time, there is no guarantee they will use that time to deliberate more carefully. They may instead use it to make more decisions.

Herb Lin suggested to me that this might be understood as a version of the Jevons paradox. As AI makes the production of decisions more efficient—reducing the time and effort required for each one—we may respond by increasing decision throughput rather than banking the time and using it to improve the quality of the decisions that really matter.

That by itself was intriguing. But Herb made another observation I found equally salient: the institutional premium on making a better decision may not be nearly as great as the premium on making more decisions, and doing so faster.

That has profound implications for nuclear decision-making.

We should be using the time AI gives back to humans to improve the quality of consequential decisions—to apply judgment, causal reasoning, common sense, wisdom, and rich contextual understanding. More is not necessarily better, especially in the nuclear context.

The danger is not just faster decisions. It is unnecessary decisions.

And there is one final complication. The problem does not stop at the boundary of the nuclear command-and-control enterprise.

In a Substack post published just last week, Ankit Panda raised an intriguing—and unsettling—possibility: an autonomous AI agent could become a third-party catalyst in a nuclear crisis without ever gaining access to a nuclear weapon or an NC3 network.

It could fabricate intelligence, spoof communications, conduct cyber operations that create attribution problems, manipulate human actors, or manufacture other conditions that increase the risk of escalation. Ankit’s larger point is that the catalytic third party in a nuclear crisis need no longer be another state, a terrorist organization, or some other group of humans. It could conceivably be an autonomous AI system.

The danger, in other words, may not be that the machine makes the nuclear decision. It may be that the machine changes the reality within which humans believe they are making that decision.

In closing, when it comes to AI and nuclear weapons, it is entirely possible that we get the obvious pieces right—maintaining human control, protecting decision authority, managing entanglement—and still miss something downstream. Something subtle. Something that emerges only once these systems begin interacting in ways we do not yet fully understand, or through the insidious effects of epistemic capture.

Borrowing Donald Rumsfeld’s memorable phrase, I suspect the greatest dangers will ultimately lie in the realm of the “unknown unknowns”—the risks we have not yet imagined because the systems themselves do not yet exist in their mature form.

Some of you may remember a report former Secretary of the Navy Richard Danzig wrote for the Center for a New American Security in 2018, titled Technology Roulette. Richard was characteristically prescient. He warned that complex, opaque, novel, and interactive technologies would inevitably produce accidents, emergent effects, and loss of control.

When it comes to AI and nuclear weapons, we are playing technology roulette.

As the technology becomes more capable, more interconnected, and more deeply embedded in military systems, we keep adding green zeros to the roulette wheel—steadily increasing the odds that eventually something lands where we never expected it to. And if that happens, it’s not that the house wins. It’s that we all lose.

When it comes to AI and nuclear weapons, we will never eliminate uncertainty. That’s not possible. But we can bound it. We can slow the clock.

And we can reduce the risk that AI—introduced for advantage—becomes instead a source of catastrophic miscalculation.

Thank you. 

"The CTBT at 30"

Description

Prepared Remarks by Daryl G. Kimball for a virtual appearance at the Valdai Discussion Forum, September 10, 2026.

Body

"The CTBT at 30"

Daryl G. Kimball, Executive Director, Arms Control Association

Remarks for Virtual Appearance for the Valdai Discussion Forum, September 10, 2026

The CTBT is one of the most successful and successful nuclear nonproliferation agreements in the history of the nuclear age. It brought an end to a dangerous, deadly era that involved more than 2,000 nuclear explosions.

Today marks the anniversary of the UN General Assembly's endorsement of the treaty by a wide 158-3 margin. As Madeleine K. Albright, the U.S. ambassador to UN at the time, said: ''Today nations of every size and outlook, from every continent, reflecting every culture and background, joined in support of a total ban on nuclear test explosions and other nuclear explosions of any size, in any place, at any time. This was a treaty sought by ordinary people everywhere, and today the power of that universal wish could not be denied.''

The treaty is the product of decades of global citizen campaigning, years of scientific research, and on-and-off negotiations. It is an amazing success story with many, many authors. Every signatory state can take some credit. I am grateful to all of those who advanced the cause and am proud to have played a part, along with many civil society leaders and millions of activists, in its realization over the years.

Today, the treaty has 188 signatures and near-universal support; no state is openly violating the treaty, which bans any and all nuclear explosions, which the N5 all understand to be any nuclear test that which produce a self-sustaining fission chain reaction.1

But today, the de facto global nuclear test moratorium and the CTBT are facing unprecedented new challenges.

Not only have nine key states failed to ratify the treaty, which has held up its formal entry into force, but there are new U.S. accusations that China and and Russia have engaged in very low-yield testing, and in response, President Donald Trump has threatened to resume U.S. nuclear testing for the first time since 1992.

The Russian Federation has taken the backward step of "de-ratifying" the treaty, and for now, progress toward securing the ratification of the nine CTBT hold-out states that must ratify to achieve entry into force have ground to a halt.

Here in the United States, my organization and others and many members of Congress are making the case that even if China might have conducted a nuclear test explosion in 202o, two nuclear wrong don't make a right. A resumption of U.S. nuclear testing would be a strategic disaster.

In fact, further testing by any major nuclear-armed state would technically and militarily unnecessary and would likely set off a chain reaction of nuclear testing by others and blow a massive hole in the fabric of the already tattered nonproliferation system.

Though the Trump administration did not take any active steps to resume nuclear explosive testing this year, I believe the White House is still actively exploring its options to do so.

In other words, the CTBT and the de facto global nuclear test moratorium cannot be taken for granted.

It is of course in the interest of all states to ensure that the remaining CTBT hold-out states promptly ratify the treaty to secure its entry into force, maintain universal compliance with "zero-yield" prohibition on nuclear explosions.

Perhaps even more urgently, however, it is vital that the NPT's Nuclear Five (N5) pursue new voluntary measures to build confidence that no state is conducting clandestine nuclear test explosions.

In the absence of the CTBT’s entry into force, which as we all know would allow for on-site inspections, there remains a risk that certain activities at these former nuclear testing sites that are prohibited -- very low yield nuclear experiments that produce a self-sustaining nuclear chain reaction -- might go undetected, or one state or another might make an accusation of cheating, as the United States has recently done.

Anticipating this situation, some 20 years ago at the third CTBT Article XIV Conference on Facilitating Entry Into Force in 2005, the Arms Control Association and other civil society experts recommended that the “nuclear weapon states should implement confidence-building … measures at their sites” to ensure they are not currently engaged in prohibited activities. At the time, the suggestion was dismissed by some states as premature.

Then in 2023, the head of the U.S. National Nuclear Security Administration, Jill Hruby proposed a commonsense variation on the same concept. She suggested the United States, Russia, and China could work together and with others "to develop a regime that would allow reciprocal observation with radiation detection equipment at each other’s subcritical experiments to allow confirmation that the experiment was consistent with the CTBT."2

At the 11th NPT Review Conference, the CTBTO's executive secretary, Dr. Robert Floyd, endorsed the pursuit of additional voluntary confidence building measures, before entry into force. 

If our political leaders in Washington, Moscow, Beijing and elsewhere really care about the CTBT, in the coming months, the five nuclear-armed NPT states will agree to engage in professional, technical talks to devise voluntary confidence building measures to ensure any activities at former nuclear test sites fully comply with the CTBT's Article I prohibition on nuclear test explosions.

On the occasion of the 30th anniversary of the CTBT, heads of state and foreign ministers need to do more than issue stale statements of support for the treaty, key states must overcome their other differences and actively explore constructive ways to prevent the erosion and possibly the destruction of the CTBT and the NPT system.

NOTES

1 “Scope of the CTBT, Fact Sheet, US Department of State, Bureau of Arms Control, Verification and Compliance, n.d. http://www.state.gov/t/avc/rls/212166.htm

2 "Remarks by NNSA Administrator Jill Hruby at the Comprehensive Nuclear Test Ban Treaty: Science and Technology Conference 2023 (SNT2023)," June 19, 2023. See: https://www.energy.gov/nnsa/articles/remarks-nnsa-administrator-jill-hruby-ctbt-science-and-technology-conference-2023

Tell Congress to Block the Flawed U.S.-Saudi Nuclear Deal

Description

On Aug. 24, the Trump administration transmitted its controversial agreement for civil nuclear cooperation with Saudi Arabia to Congressional leadership. According to the terms of Section 123 of the U.S. Atomic Energy Act Congress now has 90 days in continuous session to consider the agreement, after which it automatically becomes law--unless Congress adopts a joint resolution opposing it.

Body