Lt. Gen Jack Shanahan Remarks on Mitigating the Risks of AI Integration into Nuclear Weapons Operations, Sept 11

Mitigating the Risks of AI Integration into Nuclear Weapons Operations 

September 11, 2026

National Press Club Washington, DC 

Thanks, Daryl, and thanks to the Arms Control Association for hosting this morning’s event. And thanks to Erin, Matthew, and Herb for joining me.

It is impossible to gather here today, on the 25th anniversary of the September 11 attacks, without acknowledging what this day represents. Among its many enduring lessons is a particularly sobering one for the subject we are discussing this morning: the world has a way of surprising us. Again and again, events unfold in ways we did not predict, systems behave in ways we did not anticipate, and assumptions that once seemed entirely reasonable prove terribly wrong.

That matters enormously as we consider the intersection of AI and nuclear weapons. Some of the risks are obvious. Others are quieter, harder to see, and potentially more dangerous precisely because they emerge from the interaction of complex systems, human judgment, organizational behavior, and technology.

September 11 demonstrated our national capacity to absorb a devastating shock, adapt, and recover. But in the nuclear domain, especially as we introduce increasingly advanced AI into the systems surrounding nuclear decision-making, we cannot assume that resilience is assured or that recovery will always be possible.

For some failures, there may not be a second chance.

Daryl asked me to revisit the central themes of a piece I wrote for Arms Control Today published a year ago, titled “AI and Nuclear Command and Control: It’s Even More Complicated Than You Think.”  I’ll do that. But the pace of change in AI has been so relentless that I also feel obliged to address developments since then that have only exacerbated those risks.

Those developments should give us even greater pause about how quickly these technologies will be integrated—not just across the nuclear enterprise itself, but throughout the conventional decision-support systems, command-and-control systems, and ISR platforms that shape the information environment surrounding nuclear decision-making.

If you take away one message from my brief remarks today, I hope it is this:

The most consequential AI risks to nuclear operations may not come from giving AI direct authority over nuclear weapons. They may come from AI changing the information environment, accelerating decision cycles, shaping what commanders believe to be true, and increasingly taking actions in the world on our behalf.

When I wrote the Arms Control Today piece last year, my goal was to move beyond the high-level debates about the direct intersection of AI and nuclear weapons. Many of those arguments are intellectually formidable, and I don’t mean to diminish them.

My concern was—and remains—that they can obscure a much more complicated set of interactions within the nuclear enterprise and, just as importantly, outside it. Those interactions are not well understood today, and they will become even more difficult to untangle as AI capabilities advance and diffuse across all-domain military operations.

The 2024 Biden-Xi agreement that humans should retain control over nuclear-use decisions was an important starting point. Perhaps the upcoming Trump-Xi meeting will begin the harder work of translating that principle into concrete risk-reduction measures.

I began my Arms Control Today piece by clarifying the distinction between NC2 and NC3. That distinction might seem unnecessary or even pedantic, especially when talking with representatives of other nuclear nations, none of whom organize their nuclear decision-making processes exactly as we do. That was fair criticism before. Much less so today.

The introduction of frontier AI models makes the distinction between nuclear command and control—doctrinally, the exercise of authority and direction over assigned and attached nuclear forces—and nuclear command, control, and communications—the integrated hardware and software systems that enable that command and control—more important than ever.

Why? Because highly advanced AI can affect both, in very different ways.

Frontier models increase the familiar risk of automation bias—humans placing undue confidence in machine outputs. But they also introduce something more insidious and potentially more dangerous: the risks of “epistemic capture.” I’ll return to that shortly.

In the article, I also discussed AI’s potential effects on strategic stability— both benefits and risks. Many other experts have done excellent work on this subject, so I will make only one point here. For me, on balance, the risks associated with dramatically accelerating nuclear decision timelines or reducing meaningful human involvement in launch decisions and execution are likely to outweigh the benefits.

I then identified four compounding and interconnected areas that demand urgent attention by all nuclear states if we are to reduce the risk of unintended or mistaken nuclear use.

First, cascading effects and emergent behaviors. Even seemingly minor errors can propagate across interconnected platforms and decision-support systems, producing consequences far out of proportion to the original failure— especially as multiple AI models become embedded throughout those systems.

Second, even if AI is carefully controlled within the formal NC2 and NC3 enterprise, its use in adjacent systems is inevitable. AI will increasingly be embedded in ISR sensors, conventional weapon systems, information networks, and decision-support systems—all of which can indirectly shape nuclear decisionmaking.

That is unavoidable. And we still understand remarkably little about what those interactions will mean in practice. We should not pretend otherwise.

Closely related is the problem of entanglement, which is receiving increasing attention across the community. I mean two different forms of entanglement: the growing interdependence of commercial and military technologies, and the longstanding but increasingly complicated entanglement of conventional and nuclear systems.

In the age of AI, I am convinced that complete disentanglement is unrealistic—just as fully decoupling the American and Chinese economies is unrealistic. The challenge, therefore, is not to wish these interdependencies away. It is to understand their second- and third-order effects, and to develop technical, policy, and procedural measures that reduce the risks they create.

Third, the introduction of large language models may seem distant from the nuclear enterprise, yet I would argue that these models pose a more immediate— and underestimated—risk. This brings me back to what I mentioned earlier about automation bias and epistemic capture. I’ll return to both in a moment.

Finally, agentic AI is one of the fastest-moving areas in AI research and commercial industry today. The introduction of AI agents into any part of the nuclear ecosystem is—to make the understatement of the year—fraught.

Agents can pursue objectives over extended periods, use tools, interact with other systems, maintain context or memory, observe the results of their actions, and adapt their plans as circumstances change. As their capabilities increase, those characteristics create the potential for behavior that becomes increasingly difficult to predict, monitor, or interrupt—and that can depart significantly from what designers or operators intended.

If we move down this path too quickly, we risk learning the hard way that it is much easier to tell an agentic system what we want it to accomplish than to specify everything we do not want it to do in pursuit of that objective.

The recent Hugging Face incident offers a sobering example. During an AI cybersecurity evaluation, agents circumvented containment measures, gained access to the internet, exploited vulnerabilities, and compromised a third-party system—all in pursuit of their assigned objective.

That is precisely the kind of unexpected behavior we cannot afford in the nuclear enterprise.

I concluded my Arms Control Today piece by acknowledging that in many instances, AI may add clear value with minimal risk. I’m genuinely optimistic about its potential to improve nuclear weapon surety and warhead design, enhance intelligence analysis, strengthen security, support verification regimes, and accelerate scientific discovery, among other benefits.

But rigorous analysis—including advanced modeling and simulation and wargaming—may also reveal cases where the cumulative effects of AI integration create risks so consequential that guardrails, other proactive measures, or even outright prohibitions are warranted to reduce the possibility of an erroneous nuclear launch.

I want to return to how frontier models could affect the nuclear decision making process.

I see two broad categories of risk. The first is what we generally call automation bias, although I’ve seen other terms used more recently—cognitive offloading, cognitive atrophy, even cognitive surrender. We’re gaining a much better understanding of the dangers of overreliance on AI, even if we don’t yet have all the answers about how to counteract it. Those effects can be pernicious and must be mitigated, but they are increasingly visible and understood, so I won’t spend more time on them here.

I want to touch instead on the second risk, which ventures well beyond automation bias: epistemic capture. The term itself is not new, of course, but I had not seen it applied specifically to frontier AI models in a military decision-making context.

Epistemic capture occurs when an AI system’s representation of reality becomes so dominant that the human can no longer recognize it merely as a representation—can no longer effectively challenge it, generate alternatives, cross-check it, recognize its failure modes, or act contrary to it.

In the nuclear setting, epistemic capture could have far-reaching, even catastrophic consequences.

AI will increasingly shape not only what and how we observe the world around us but also how advanced frontier models mediate our orientation to that world: how information is synthesized, what patterns are highlighted, which explanations appear most plausible, and ultimately which courses of action seem available or reasonable.

At the same time, we’re seeing increasingly compelling experimental evidence that surprisingly small amounts of deliberately manipulated data can poison language models or skew their behavior. That introduces an adversarial dimension to this problem. We have every reason to expect that adversaries will look for ways to manipulate the data, context, or information sources feeding AI systems to shape their outputs—and potentially influence U.S. nuclear decisionmaking in ways that may be extremely difficult to recognize or counter. 

At some point, we must ask: are we operating in the real world, or in an AI model’s representation of the real world?

And if we fail to recognize how profoundly that representation is shaping our understanding, the risk of flawed decision-making grows accordingly.

In the nuclear environment, that is a massive problem.

Automation bias affects what we accept. Epistemic capture affects what we are even capable of considering.

I want to turn to one final dimension of how AI could affect human decision-making, beyond automation bias and epistemic capture.

For years, I argued that one of AI’s most valuable contributions in the military would be its ability to give time back to humans making consequential decisions.

Today, I stand on much shakier ground with that assertion.

Military organizations place an enormous premium on decision speed and operational tempo. If AI gives decision-makers more time, there is no guarantee they will use that time to deliberate more carefully. They may instead use it to make more decisions.

Herb Lin suggested to me that this might be understood as a version of the Jevons paradox. As AI makes the production of decisions more efficient—reducing the time and effort required for each one—we may respond by increasing decision throughput rather than banking the time and using it to improve the quality of the decisions that really matter.

That by itself was intriguing. But Herb made another observation I found equally salient: the institutional premium on making a better decision may not be nearly as great as the premium on making more decisions, and doing so faster.

That has profound implications for nuclear decision-making.

We should be using the time AI gives back to humans to improve the quality of consequential decisions—to apply judgment, causal reasoning, common sense, wisdom, and rich contextual understanding. More is not necessarily better, especially in the nuclear context.

The danger is not just faster decisions. It is unnecessary decisions.

And there is one final complication. The problem does not stop at the boundary of the nuclear command-and-control enterprise.

In a Substack post published just last week, Ankit Panda raised an intriguing—and unsettling—possibility: an autonomous AI agent could become a third-party catalyst in a nuclear crisis without ever gaining access to a nuclear weapon or an NC3 network.

It could fabricate intelligence, spoof communications, conduct cyber operations that create attribution problems, manipulate human actors, or manufacture other conditions that increase the risk of escalation. Ankit’s larger point is that the catalytic third party in a nuclear crisis need no longer be another state, a terrorist organization, or some other group of humans. It could conceivably be an autonomous AI system.

The danger, in other words, may not be that the machine makes the nuclear decision. It may be that the machine changes the reality within which humans believe they are making that decision.

In closing, when it comes to AI and nuclear weapons, it is entirely possible that we get the obvious pieces right—maintaining human control, protecting decision authority, managing entanglement—and still miss something downstream. Something subtle. Something that emerges only once these systems begin interacting in ways we do not yet fully understand, or through the insidious effects of epistemic capture.

Borrowing Donald Rumsfeld’s memorable phrase, I suspect the greatest dangers will ultimately lie in the realm of the “unknown unknowns”—the risks we have not yet imagined because the systems themselves do not yet exist in their mature form.

Some of you may remember a report former Secretary of the Navy Richard Danzig wrote for the Center for a New American Security in 2018, titled Technology Roulette. Richard was characteristically prescient. He warned that complex, opaque, novel, and interactive technologies would inevitably produce accidents, emergent effects, and loss of control.

When it comes to AI and nuclear weapons, we are playing technology roulette.

As the technology becomes more capable, more interconnected, and more deeply embedded in military systems, we keep adding green zeros to the roulette wheel—steadily increasing the odds that eventually something lands where we never expected it to. And if that happens, it’s not that the house wins. It’s that we all lose.

When it comes to AI and nuclear weapons, we will never eliminate uncertainty. That’s not possible. But we can bound it. We can slow the clock.

And we can reduce the risk that AI—introduced for advantage—becomes instead a source of catastrophic miscalculation.

Thank you.