What Sisson and Jiang Actually Propose

Melanie Sisson, a senior fellow at the Brookings Institution, and Tianjiao Jiang, an associate professor at Fudan University, are longtime participants in the Brookings-Tsinghua US-China AI and National Security Dialogue, a track-two channel running since 2019. In a paper published this month, they recommend a formal ban on AI autonomously launching nuclear weapons or attacking nuclear command, control and communications systems, and the same human-authorization requirement extended to cyberattacks on critical infrastructure: finance, health, energy and transport. They also propose a dedicated US-China military hotline for incidents triggered by AI errors or AI-enabled cyberattacks, built on existing defense communication channels, plus a joint working group to agree on what "meaningful human control" actually means, since the two countries currently use different terms for it.

The recommendations build directly on a November 2024 agreement in which Presidents Biden and Xi affirmed that humans, not AI, should control the decision to use nuclear weapons. What Sisson and Jiang are proposing is the first attempt to turn that single-sentence principle into a working mechanism for a cyberattack scenario, not just a launch decision.

Why It Matters: The Decision Window Is the Problem

Jiang names three specific obstacles to any of this working in practice. Cyberattacks can execute in milliseconds, faster than a human reviewer can physically respond. Attribution is difficult: it is often unclear in the moment whether a state or a non-state actor launched an AI-enabled attack. And AI system opacity makes it hard for either side to assess what the other's systems can actually do, which pushes both toward worst-case assumptions about the other's capability. A hotline, not a treaty, is the proposed answer, because a treaty cannot be invoked in the minutes an actual incident would leave.

The critical-infrastructure clause reaches further than militaries. The standard proposed, human authorization required before any cyberattack capable of property destruction, environmental contamination, social chaos, or widespread illness, injury or death, is close to a template for how any operator of finance, health, energy or transport systems could eventually be asked to prove it keeps a human in the loop on AI-linked incidents.

Timing: Ahead of a Meeting, Not Instead of One

The recommendations were published ahead of a planned September 24, 2026 meeting between Presidents Trump and Xi in Washington, and ahead of an anticipated formal government-level US-China AI dialogue. Sisson and Jiang frame the paper as material for negotiators to draw on, not an agreement already reached, and neither government has endorsed the specific proposals.

Track-two dialogues, expert channels with informal government access but no negotiating authority, have a real history of supplying the vocabulary that formal agreements later adopt; the 2024 Biden-Xi nuclear-control line itself traces back to a similar process. Whether any of this hotline or red-line language resurfaces after September 24 is the thing worth watching next.

What This Means If You Run Critical Infrastructure

None of this is binding today. But the proposed critical-infrastructure clause previews the shape of AI incident-response and human-oversight expectations that finance, health, energy and transport operators are likely to face eventually, not only militaries. Treat this paper as an early marker for how "human in the loop" gets formally defined for AI-security incidents, and check back after the Trump-Xi meeting for whether either government references it.