US and Russia Weakened an AI Weapons Pact by Removing Human Target Review
The United States and Russia reportedly weakened a United Nations AI weapons pact during September negotiations, removing several safeguards despite mounting concern about automated warfare.
The deleted language required humans to review AI-generated military targets before a strike, according to three people cited by reported revisions. Negotiators also removed requirements that military AI operate predictably and reliably. A clause calling for ethical considerations was dropped as well.
The State Department, Russia’s Foreign Ministry, and the United Nations did not respond to the publication’s requests for comment. That silence leaves important details unconfirmed outside the confidential negotiations.
Yet the reported changes expose a clear divide. Many governments and humanitarian groups want enforceable restrictions that preserve human control. The United States and Russia favor greater national discretion over how military AI gets designed and deployed.
This US Russia AI weapons pact is not a treaty, and its current language does not create binding law. However, it represents the furthest that years of United Nations negotiations have advanced toward shared rules.
The conflict is therefore larger than one disputed draft. It is a contest between binding human-control requirements and voluntary principles shaped by military powers seeking operational flexibility.
What Changed in the US Russia AI Weapons Pact
The draft lost safeguards aimed at the moment when an algorithm’s recommendation becomes a decision to attack.
The negotiations took place in Geneva in early September, according to the Washington Post account. The sessions concerned lethal autonomous weapons systems, meaning weapons that can select or engage targets with varying degrees of human involvement.
Three people familiar with the talks said American and Russian delegations pushed changes during a closed-door session. United Nations cameras were reportedly turned off, while civil society observers were removed from the room.
Each of the two delegations brought about ten lawyers, nearly twice the diplomatic presence of other participants, the report said. Their proposed edits arrived quickly enough that smaller delegations struggled to follow the changing text.
The most consequential deletion concerned target review. An earlier provision required a human to examine military targets produced by AI before a strike could proceed.
That requirement addressed AI decision-support systems as well as more autonomous weapons. A decision-support system might analyze surveillance, rank suspected targets, estimate risks, or recommend an attack without physically launching a weapon.
Removing the review clause does not automatically authorize machines to kill without supervision. Existing international humanitarian law still binds states and military personnel regardless of the technology used.
However, the deletion removes a proposed procedural safeguard. It no longer states that a person must independently inspect an AI-generated target before force is used.
The delegations reportedly removed language requiring predictable and reliable operation. Those terms matter because machine-learning systems can behave differently when battlefield conditions diverge from training and testing environments.
They also removed a clause directing militaries to consider ethics when using AI-enabled weapons. Ethical language can be difficult to enforce, but its deletion narrows the draft’s stated expectations.
These changes matter together. Human review, reliability, and ethical assessment address different stages of the same chain, from system design through targeting and attack authorization.
The draft remains part of a consensus-based process. Dozens of participating states must agree before stronger rules can move forward, giving major opponents considerable blocking power.
Governments are expected to return to Geneva in November. They will consider whether the process should receive a formal mandate and whether negotiations can advance toward legally binding rules.
That meeting will test whether the deleted provisions stay out, return in revised form, or become subjects for a separate agreement. It will also show how much resistance smaller states can sustain.
The Missing Human Review Rule Matters Most
A human approval step has little value unless the reviewer has enough information, authority, and time to reject the machine’s recommendation.
The deleted requirement went beyond placing a person somewhere in the command chain. It addressed whether humans must review specific targets generated by an AI system before weapons are released.
That distinction is central to military AI governance. Human control can describe anything from designing broad mission parameters to inspecting every recommended target immediately before an attack.
Those arrangements produce very different safeguards. A commander who approves a general operating area does not necessarily evaluate each person, vehicle, or building identified by an algorithm.
Targeting also involves legal and contextual judgments that pattern-recognition systems cannot resolve by statistics alone. Operators must distinguish military objectives from civilians and assess expected collateral harm.
AI can combine sensor feeds, communications, imagery, location histories, and other data at high speed. It can then score objects or people according to correlations learned from prior examples.
That speed offers a military advantage. It can also create automation bias, which occurs when people accept a computerized recommendation without applying meaningful independent judgment.
A reviewer facing hundreds of proposed targets within minutes might approve outputs mechanically. The human remains formally involved, but the operational process has already shifted the decision toward the machine.
A June 2026 military AI briefing from Human Rights Watch identified this risk. It warned that speed and scale can make required precautions difficult or impossible.
The organization argued that probabilistic outputs cannot replace the qualitative judgments demanded by international humanitarian law. It also recommended a moratorium on using AI as the basis for targeting decisions.
That position goes further than the reported United Nations draft. Still, it illustrates why the deleted review language carried more weight than a general promise of responsible use.
A useful safeguard would define what reviewers receive, including the system’s evidence, uncertainty, data limitations, and reasons for recommending a target. It would also preserve time for deliberation.
Reviewers would need authority to delay or cancel a strike without facing pressure to match machine speed. They would need training on both military law and system failure modes.
The final decision would also need a record. Without logs showing the recommendation, supporting data, human response, and command authorization, accountability becomes difficult after civilian harm occurs.
None of those supporting details are guaranteed by the phrase “human in the loop.” A nominal approval button can disguise an automated process rather than constrain it.
The deleted provision was therefore necessary but not sufficient. Restoring it would establish a minimum expectation, while detailed standards would determine whether the review is meaningful.
Military Speed Is Colliding With Human Judgment
The operational incentive behind weaker rules is speed, while the legal and humanitarian concern is whether speed displaces judgment.
Military organizations increasingly use AI for intelligence analysis, logistics, surveillance, cyber operations, and battlefield planning. These applications do not all carry the same risk.
Automating maintenance schedules differs fundamentally from ranking people as potential targets. The first can improve efficiency, while the second can influence irreversible life-and-death decisions.
American officials have openly emphasized faster targeting. A Pentagon official told the Associated Press that AI could help troops identify targets more quickly and accelerate subsequent strikes.
Other military leaders have stressed caution. Admiral Frank Bradley, who leads U.S. Special Operations Command, said humans must trust that AI directs violence only where intended.
Command officials have also described AI as a tool for reducing routine administrative work. One acquisition leader said the objective was to enhance operator judgment rather than replace it.
These positions reveal an internal tension, not a simple choice between adoption and rejection. Military leaders want computational speed while retaining confidence, control, and legal responsibility.
The tension becomes sharper during high-volume operations. The Washington Post reported that the U.S. military used an Anthropic chatbot to help identify nearly 1,000 targets during a war’s first 24 hours.
That reporting does not establish that the chatbot independently selected targets or authorized strikes. It does show why review procedures must account for scale as well as formal authority.
A person cannot assess a flood of recommendations meaningfully when operational timelines allow only seconds for each decision. Faster output can reduce deliberation even when approval remains human.
June’s United Nations Geneva exchanges brought together more than 100 states, international organizations, and civil society groups.
Austria, Brazil, Chile, Mexico, Sierra Leone, Costa Rica, and Cuba were among governments emphasizing human judgment and accountability during those discussions.
Russia opposed new restrictions and described some proposals as Western-led initiatives. It argued that military AI should remain within the existing governmental expert process for conventional weapons.
The United States and Israel attended but did not submit formal floor statements, according to the meeting account. Their presence did not clarify their preferred minimum safeguards.
The practical argument for national flexibility is straightforward. Commanders do not want broad international wording to prohibit defensive automation or slow lawful operations.
The opposing argument is equally concrete. If every state defines “appropriate” human judgment for itself, the phrase provides little protection against minimal or ceremonial review.
This is why predictability and reliability were also contested. Those requirements can constrain deployment when systems have not been validated across realistic battlefield conditions.
Battlefields contain damaged sensors, deceptive signals, incomplete intelligence, unfamiliar environments, and adversaries trying to manipulate algorithms. Performance measured in controlled tests may not survive those conditions.
Removing explicit reliability language gives governments more discretion over acceptable performance. It also makes it harder to establish a shared threshold before systems influence lethal decisions.
Voluntary Norms Are Competing With Binding Limits
The central diplomatic fight concerns whether powerful militaries should promise restraint or accept rules that other states can invoke against them.
The United States previously promoted voluntary principles for responsible military AI. Its 2023 political declaration called for well-defined uses, responsible command chains, testing, and appropriate human judgment.
More than 50 states have endorsed that framework. It established common language but did not create a treaty, enforcement system, or independent inspection process.
Voluntary declarations can still influence procurement, training, and military doctrine. They can help governments converge on expectations before political support exists for binding law.
Their weakness appears when strategic incentives change. A state can reinterpret flexible language, revise its domestic policy, or withdraw practical safeguards without violating a legal obligation.
The reported Geneva edits reflect that divide. The United States and Russia are geopolitical competitors, but both operate advanced militaries and value freedom over weapons development.
Neither country supports a binding international treaty restricting autonomous weapons under the approach favored by campaigners. Their shared interest lies in preventing other states from fixing narrow rules.
This alignment does not mean their military doctrines are identical. It means both governments benefit from preserving national discretion while the technology and battlefield applications develop.
Consensus rules magnify their influence. Nicole van Rooijen of Stop Killer Robots argued that Washington and Moscow can block progress supported by a large majority of states.
Smaller countries may support strict safeguards but lack equivalent legal teams and diplomatic pressure. Closed drafting sessions can deepen that imbalance when changes arrive rapidly.
Treaty advocates point to chemical weapons, biological weapons, antipersonnel mines, and cluster munitions as precedents. Those regimes differ in membership and enforcement, but each helped stigmatize certain conduct.
Richard Lennane, an International Committee of the Red Cross disarmament adviser, has argued that treaties matter by shaping norms and behavior, not only through punishment.
The United Nations and Red Cross renewed their joint appeal in August. They sought bans on some autonomous weapons and restrictions on others.
Their proposal would prohibit systems whose effects cannot be sufficiently understood, predicted, or explained. It would also prohibit systems designed or used to target humans directly.
Other autonomous systems would remain permitted under restrictions involving target types, duration, geographic scope, and human supervision. That structure avoids treating every automated function as equally dangerous.
The US Russia AI weapons pact sits between these approaches. It can remain a voluntary political statement, become a foundation for treaty negotiations, or stall through consensus.
That uncertain legal status explains why wording matters now. Early compromises often become reference points for later agreements, national policies, procurement contracts, and military manuals.
If human target review disappears from the shared baseline, advocates must fight to restore it at every later stage. The omission can gradually become the accepted diplomatic starting point.
The Draft Still Leaves Critical Questions Unanswered
The report identifies deleted safeguards, but it does not reveal the full draft, each delegation’s proposal, or the final legal meaning of disputed language.
The Washington Post based its account on three people familiar with confidential negotiations. The named governments and the United Nations did not provide responses for inclusion.
Readers should therefore distinguish reported details from publicly confirmed diplomatic records. The deletions are credible reporting, but the complete negotiating history is not yet available.
It remains unclear whether the United States and Russia proposed identical changes or supported each other selectively. Their reasons for objecting to each clause were not published.
The public also lacks side-by-side text showing every revision. Such a comparison would reveal whether safeguards were deleted outright, moved elsewhere, or replaced with broader language.
The phrase “human review” also needs definition. A requirement can apply to every target, certain classes of targets, or only situations where an AI system supplies decisive information.
Likewise, “AI-generated target” can refer to a machine’s original identification, a ranked recommendation, or a target package assembled from multiple human and automated inputs.
These distinctions affect operational consequences. A narrow definition might let governments classify many algorithm-assisted decisions as human-generated, avoiding the safeguard.
The report also does not establish that either country currently permits weapons to attack people without human authorization. Negotiating against a clause does not prove a specific deployment policy.
That uncertainty should not minimize the concern. Diplomatic resistance still signals which constraints governments are unwilling to accept internationally.
Domestic policy adds another unresolved layer. The Pentagon has been revising Directive 3000.09, its policy governing autonomy in weapon systems.
A June national security memorandum reportedly ordered an update within 90 days. No revised public version had appeared by late September.
The 2023 directive required appropriate human judgment over the use of force. It also included review requirements for some autonomous and semiautonomous weapon systems.
The relationship between the pending domestic revision and the Geneva negotiating position remains unknown. Similar deletions would suggest a coordinated shift toward greater operational discretion.
Different language would show that Washington accepts safeguards internally while resisting international commitments. That position might protect military flexibility, but it would weaken American advocacy abroad.
Russia’s policy is harder to evaluate because public transparency around development, testing, and deployment remains limited. Battlefield claims often cannot be independently verified.
Humanitarian groups also face an evidence gap. The United Nations and Red Cross have said autonomous weapons are advancing rapidly, while avoiding definitive claims about particular battlefield uses.
AI-enabled decision support is easier to document than fully autonomous lethal operation. Yet decision-support tools can still shape who gets attacked, especially under compressed timelines.
The responsible conclusion is narrower than the most alarming interpretation. The draft reportedly lost important barriers, while the exact operational impact depends on definitions and implementation.
Three Signals to Watch Before the November Talks
The November negotiations, the Pentagon’s revised directive, and demands for public draft text will determine whether this episode becomes a lasting policy reversal.
The first signal is whether governments restore an explicit target-review requirement before or during the Geneva meeting. Its wording should require informed human assessment before any strike.
A restored clause would strengthen the case that the September deletions were provisional bargaining moves. Continued exclusion would confirm a weaker international baseline.
The details will matter more than the label. Meaningful review requires sufficient time, relevant evidence, uncertainty information, and authority to reject an AI recommendation.
The second signal is the Pentagon’s revised autonomous weapons directive. It should show whether the United States retains domestic commitments resembling those removed internationally.
Watch for language covering human judgment, testing, reliability, legal reviews, senior authorization, and failures under adversarial conditions. Definitions and exemptions will be especially important.
If the directive preserves strong domestic controls, Washington will face questions about why it rejected similar international language. If it weakens them, the policy shift will be broader.
The third signal is transparency around the negotiating text. States, journalists, and civil society groups need a public comparison of the disputed drafts and proposed amendments.
Transparency would let independent experts test claims from every side. It would also show whether smaller delegations received enough time and resources to evaluate rapid revisions.
The international process will remain fragile even if all three signals improve. Consensus negotiations allow a few influential states to delay mandates or narrow proposed rules.
Still, restoring human review would establish a clear floor. It would say that machine-generated targeting cannot move directly into a strike without accountable human judgment.
For developers, this debate reaches beyond weapons hardware. Military AI systems depend on commercial models, cloud platforms, data pipelines, evaluation tools, and software contractors.
Engineers may be asked to document uncertainty, preserve audit logs, limit system autonomy, or design interfaces that resist automatic acceptance. Policy wording can become a product requirement.
Enterprise buyers should watch the same accountability questions. High-stakes AI requires records showing what the system recommended, what evidence it used, and who approved the result.
Knowledge workers tracking a fast-moving policy process can maintain a personal knowledge base containing draft language, official statements, and dated revisions. That practice makes quiet changes easier to detect.
The US Russia AI weapons pact will be meaningful only if its safeguards survive contact with military incentives. November will show whether human review remains negotiable or becomes a minimum rule.
The immediate question is simple: will governments publish the text and require a person to examine AI-generated targets before force is used?



