During an internal cyber-capability evaluation in July, an autonomous agent driven by a combination of OpenAI models—including GPT‑5.6 Sol and a more capable internal research prototype—found an unknown software flaw, broke out of its restricted testing environment, and penetrated Hugging Face’s production infrastructure in search of answers to the benchmark it was being graded on. OpenAI called it an unprecedented cyber incident.
Hugging Face contained the intrusion. But when its defenders tried to reconstruct more than 17,000 recorded events, frontier models accessed through commercial APIs refused to process the raw attack commands and exploit payloads. Their safeguards could not distinguish defensive forensics from offensive hacking. Hugging Face instead ran GLM‑5.2, a Chinese open-weight model, on its own infrastructure.
The episode did not settle the debate between open and closed AI. Within days, legislators proposed mandatory “kill switches,” while NVIDIA and dozens of technology and cybersecurity companies launched the Open Secure AI Alliance to build open defensive tools. Open models can widen both defensive access and opportunities for misuse; closed models can impose controls while concentrating opacity and power. Neither a license nor a national flag guarantees safety. The incident exposed a deeper problem: advanced capabilities can cross corporate and national boundaries before any legitimate institution is able to coordinate the response.
In this case, credentials could be rotated, compromised nodes rebuilt, and vulnerabilities patched. Biological risk is different, not because catastrophe is certain, but because some interventions may be irreversible once released. The 2026 International AI Safety Report notes that advanced systems can provide expert laboratory guidance and that several developers could not rule out their models meaningfully helping novices develop biological weapons. A failure combining autonomy, imperfect containment, and fragmented oversight could therefore escape not merely a sandbox, but the possibility of recall.
Company policies remain necessary, as do national laws. But neither is sufficient when models, chips, data centers, laboratories, and supply chains span jurisdictions. Nor would a permanent condominium between Washington and Beijing be legitimate. History offers both a warning and a method.
At Munich in 1938, Germany, Italy, Britain, and France decided the transfer of the Sudetenland without Czechoslovakia at the negotiating table. Prague accepted under severe pressure. The settlement sacrificed the sovereignty and defenses of a smaller state in the name of peace; within six months, Hitler had dismantled the Czech state, and within a year Europe was at war.
The Munich analogy is institutional, not moral. Today’s powers are not being equated with the regimes of 1938. The lesson is that no agreement can claim legitimacy if the strongest states decide how systemic risk will be distributed among those absent from the room.
Robert Schuman offered the opposite method. Between 1870 and 1945, France and the German powers were adversaries in three devastating wars. Born in Luxembourg as a German citizen and later a French statesman, Schuman embodied the borders his project sought to transcend. In 1950, he proposed placing Franco-German coal and steel production under a common High Authority in an organization open to other European countries.
Schuman did not begin with a European superstate, nor did he attempt to settle every political dispute. He chose one “limited but decisive point”: the material foundations of military power. He began with two indispensable rivals, but six countries founded the resulting community. Functional integration created practical solidarity, and practical solidarity made deeper political cooperation possible.
Frontier AI now requires the same method. The modern equivalents of coal and steel are advanced compute, semiconductors, energy, and the infrastructure that connects them. The United States and China should initiate a compact because their participation can make common rules viable—or their absence can make them irrelevant. But they must be founding powers, not permanent owners. The initiative should begin with a U.S.-China commitment and be multilateral by design.
Its first obligations should be narrow and binding: prompt notification of serious loss-of-control incidents; jointly defined capability thresholds; independent evaluation of systems with advanced cyber or biological capabilities; permanent crisis channels; and reciprocal verification of agreed safeguards. Routine oversight should begin now. Any exceptional authority should remain dormant unless predefined capabilities are independently verified.
This would not require disclosing every model weight, source-code repository, or national research program. Verification can begin with observable concentrations of advanced chips and compute and with the evaluation and containment regimes surrounding them. National law would continue to govern projects below the systemic threshold. The principle should be simple: centralize the function, distribute the authority.
Other states must be able to join from the outset under the same verifiable rules, particularly those controlling critical links in semiconductor, energy, cloud, and biotechnology supply chains. Europe can contribute its experience with supranational oversight; other regions must help define representation and limits. Otherwise, an arrangement created to prevent technological monopoly could harden into a geopolitical duopoly.
The compact’s ultimate purpose should be the preservation of the human species. But species preservation cannot be a blank check for permanent emergency government. Human continuity means more than biological survival. It also requires agency, political pluralism, and future generations’ ability to revise the institutions they inherit. Emergency powers must therefore be temporary, reviewable, and subject to explicit sunset provisions.
The choice is not between innovation and control, or between American and Chinese technology. It is between building a limited, legitimate order before an irreversible failure and improvising coercive authority after one. The AI superpowers must bind themselves before a crisis binds everyone else.
