AMC Insights header

What 80 Years of Arms Control Teaches Us About Military AI

Wilfred Wan

Haimi Tefera, Kundan Kumar, Gabriel Coutinho & Srijani Manna

This series presents top outputs from the AMC Arms Control & AI Governance Research Sprint. The event held in April 2026, brought together approximately 60 arms control professionals, early-career researchers, and graduate students, to work intensively over two days with the arms control datasets from AMC Data.

On 28 February 2026, the first day of US-Israeli strikes on Iran, a Tomahawk missile destroyed the Shajareh Tayyebeh elementary school in Minab. Iranian authorities recorded 168 dead, more than 110 of them children. The likely cause, according to a Military Times investigation, was a targeting failure, not a malfunction: the Maven Smart System—Palantir’s AI-driven intelligence platform used by the Pentagon—had processed stale data that still classified the site as a military compound. The school had been a functioning civilian institution for over a decade. The algorithm did not know. And in the compressed tempo of a kill chain moving at machine speed, neither, effectively, did the humans deferring to it.

This is the central challenge of our time: how do you govern a weapon that is comparatively invisible, extremely dual-use, and improving faster than any diplomatic process can track?

To answer that, we went back to the records. Our analysis of 128 arms control treaties spanning 1817 to 2021 from the Alva Myrdal Centre's database produced two findings that should give any AI governance optimist pause.

40% of All Regulated Weapons Have No Oversight

Across the 128 agreements, four levels of oversight emerge. At the top: verified compliance, where an independent body—like the International Atomic Energy Agency (IAEA) for example—has access rights and can confirm what states say they are doing. To use a metaphor, it’s the teacher checking your homework. Below that: demonstrated compliance, where states self-report but nobody verifies. Here, to extend the metaphor, you check your own homework. Then consultation, where parties can raise concerns but there is no binding mechanism. There is some class discussion, but no homework. And at the bottom: nothing. There is no school.

The Compliance Architecture Spectrum in Arms ControlZoom image

Soberingly, it is that bottom category that is the most populated. Nearly 40% of all arms control agreements operate with no oversight whatsoever. At 40%, this cannot be an oversight. It is a political choice—and a fragile one. While deteriorating trust means that no treaty is safe, those without enforcement mechanisms offer nothing to slow the collapse.

Verified compliance has been dying for thirty years

Our second finding concerns what we call the “Great Expiry”. Between the 1970s and the 1990s, the world built something remarkable: a genuine infrastructure of independent inspection. The Strategic Arms Limitation Talks (SALT), The Intermediate-Range Nuclear Forces (INF), the Strategic Arms Reduction Treaty (START), the Chemical Weapons Convention (CWC)—this golden era produced 17 new agreements with independent verification mechanisms in the 1990s alone.

Then, almost entirely, they stopped. The 2000s produced zero new verified compliance agreements. The 2010s and 2020s became an era of dismantlement rather than construction. The INF Treaty was abandoned in 2019. New START, one of the two verified compliance treaties from the 2010s, expired in February 2026 with no successor in sight, leaving the world's two largest nuclear arsenals without a formal monitoring framework for the first time in decades.

Compliance Architecture Over Time (1920s-2010s)Zoom image

The lesson is not that verification is impossible. It is that it requires a specific political condition: mutual trust at a moment of high mutual vulnerability. That window—open between the late Cold War and the collapse of post-Soviet optimism—has closed. The question is whether, with autonomous weapons, we can manufacture that window rather than wait for it.

What this means for military AI governance

At first glance, the parallels are discouraging: like biological agents, an autonomous weapons system can be developed on civilian hardware (decentralised threats); a model built for logistics or surveillance can be re-tasked for targeting (dual-use); and the same major powers that blocked a verification protocol for the Biological Weapons Convention (BWC) in 2001 are also the ones now resisting binding rules on autonomous weapons (lack of political will). If military AI follows the BWC path, treaties get signed, reporting stays voluntary, and nobody verifies anything. Every state gives itself an A+, whether they deserve it or not.

However, history also offers a more hopeful lesson—one about process rather than outcome.

In 2007, a coalition of states frustrated by veto paralysis in the UN Convention on Certain Conventional Weapons (CCW) launched what became the Oslo Process on cluster munitions. It worked differently from the parent convention in four ways: (1) states committed to a shared goal before negotiations began; (2) a two-year deadline prevented indefinite delay; (3) voting was permitted, removing any single state's veto; and (4) civil society groups were included alongside governments. The result was the Convention on Cluster Munitions, signed by 111 states. The United States, Russia, and China did not sign—and both Ukraine and Russia have openly used cluster munitions, despite them being disproportionately detonated by children who mistake them for toys. But 111 signatories exist where previously there were none. The norm has imposed real reputational costs on users that did not exist before Oslo.

The same approach is available for autonomous weapons. Rather than waiting for CCW consensus—where the states most actively developing autonomous systems are the ones doing the blocking—a coalition of genuinely concerned states could pursue an Oslo-style process: set a goal, set a deadline, allow voting, and include civil society. The resulting treaty will not immediately bind the largest military powers. But standards, once established, have a way of spreading.

Building a New Window of Opportunity

We went into this research expecting to find a story about the limits of arms control. What we found instead was a story about timing and process. The most durable verification regimes were built when adversaries had everything to lose from undetected cheating and no alternative means of knowing whether it was happening. That combination of stakes and urgency is hard to manufacture—but it is not impossible.

Humanity may be approaching a comparable window for military AI: a period before autonomous systems are so embedded in military doctrine that no state can afford to constrain them, when the risks are visible enough to motivate action, but the damage has not yet compounded. Serious states should stop waiting for CCW-style consensus and start building the coalition that can act before the window closes.

After all, the treaties that were never written are the ones most regretted.

The authors conducted this research as part of the Uppsala University Arms Control Research Sprint, April 2026. Data drawn from the Alva Myrdal Centre for Nuclear Disarmament's Arms Control Agreements Database.

FÖLJ UPPSALA UNIVERSITET PÅ

Uppsala universitet på facebook
Uppsala universitet på Instagram
Uppsala universitet på Youtube
Uppsala universitet på Linkedin