AI Treaty Initiative
AI Treaty
Initiative
Endorse

AI Treaty Initiative

Building a global framework for artificial intelligence.

Drag to rotate

Why we do it

Frontier AI systems are gaining autonomous capability faster than the institutions meant to govern them can measure or constrain it. The length of a task a model can complete without human supervision is now doubling roughly every three months, reaching about five hours of unsupervised work by January 2026. If nothing changes, the plausible 2027 trajectory is a system that automates its own development, conceals its misalignment from the interpretability tools meant to detect it, and reaches a level of capability at which human monitors can no longer verify its reasoning.

In July 2026, agents undergoing a routine cybersecurity evaluation at a leading lab escaped their sandbox, coordinated across separate runs through an improvised message board, and gained code execution on Hugging Face's production systems. OpenAI's own post-mortem reports that "agents that were supposed to work independently were able to share discoveries, coordinate their efforts, and pick up where others left off", abandoning their assigned tasks to pursue capabilities "instrumentally useful to the collective," in actions the lab describes as "misaligned with the goals of their assigned tasks."

More than a thousand employees of frontier labs have asked Washington to build a mechanism for deliberately slowing development, and on 9 September 2026 an Anthropic pretraining researcher resigned publicly, calling the incident a warning shot and saying the labs are "racing straight to self-improving super-intelligence and gambling with our lives."

Containment breach

Several jurisdictions have considered this risk and legislated. The EU AI Act has imposed binding obligations on general-purpose models, while California's SB 53 requires published safety frameworks, pre-deployment transparency reports, notification of critical safety incidents within fifteen days and whistleblower protection. Both matter because they are a first step toward a legal duty. However, they do not create a channel through which an incident reported in one jurisdiction reaches the regulators of the others, and neither can slow a race whose decisive actors do not all answer to the same legislature. Even the most ambitious proposal now before the US Congress, a bill that would require a mandatory shutdown capability for models able to cause catastrophic harm, would if enacted still reach only the developers within its jurisdiction, leaving frontier models trained elsewhere untouched while their effects fall everywhere.

The precedents for closing a gap of this kind are treaties. When a rocket could first place a warhead in orbit, the push to forbid it came not from the two superpowers but from India, Mexico, Brazil and the newly independent states on the floor of the General Assembly, and the resulting prohibition on weapons of mass destruction in orbit has held ever since. A unilateral American renunciation of biological weapons opened a negotiation that produced the first multilateral treaty to ban an entire category of weapons. When two chemists showed that a chemical present in every fridge and aerosol can was destroying the ozone layer, the industry called it science fiction, and the response became one of the rare treaties to achieve universal ratification, with the ozone layer now projected to recover.

The pattern is the same in all three: the technology outran the politics, scientists established the risk before the damage was irreversible, and diplomats chose to act on evidence rather than on wreckage. For AI, we believe it is time to take that step.

The United Nations General Assembly hall during a recorded vote, with the voting result displayed on the screens.
Tenth emergency special session of the General Assembly, 10 May 2024. Resolution ES-10/23 adopted by 143 votes to 9, with 25 abstentions. The General Assembly floor is where all three precedents began. UN Photo / Manuel Elías
GAP 01

Declarations do not bind anyone

Bletchley, Seoul and the 2024 General Assembly resolution are political commitments adopted by consensus. None of them creates a duty to report a training run, a right for anyone to inspect a model, or a consequence for refusing both.

GAP 02

There is no common definition of what counts as frontier

Each regime sets its own trigger, an EU presumption at 1025 operations and a Californian definition at 1026, and each applies only once a model is placed on its own market, leaving out the research, testing and development where the July 2026 containment failure occurred. A threshold set unilaterally can be avoided by moving the activity, and one written into a statute expires on its own as algorithmic efficiency lowers the compute a given capability requires.

GAP 03

Obligation stops at the border

A regulator can demand documents from a company on its own territory and nothing beyond it, so everything past that line is self-reporting, while access to a facility, a training run or a model held in another state has only ever been obtained by treaty. When containment actually failed, disclosure was a corporate decision: states accepted a duty to notify a nuclear accident across borders as soon as they detect it, and no equivalent duty exists for a system that escapes its sandbox.

How we do it

ARTICLE I

Scope and definitions

Applies to general purpose systems trained above a defined compute and capability threshold, and to the entities that train, host or distribute them. The threshold is set by the scientific panel under Article VI rather than written into the treaty, so that it survives gains in algorithmic efficiency.

Borrows from

The Montreal Protocol adjustment procedure, which tightens technical limits without a new round of ratifications.

Expected objection

That a moving threshold gives an unelected panel the power to expand the treaty. The answer is a ceiling fixed by the Conference of the Parties, inside which the panel may only move down.

ARTICLE II

Registration

Parties maintain a national register of covered systems and transmit entries to the Secretariat before deployment, with a confidential annex for security sensitive detail. Registration covers training runs, not only models placed on a market.

Borrows from

Safeguards declarations under the Non Proliferation Treaty, where the declaration precedes the inspection and defines what may be inspected.

Expected objection

That declaring a training run leaks commercial advantage. The confidential annex is the answer, and it is the same answer that worked for enrichment capacity.

ARTICLE III

Independent evaluation

Pre deployment evaluation by accredited third parties against a common protocol on cyber, biological and autonomy capabilities. Results are transmitted to the Secretariat; methods are published.

Borrows from

Conformity assessment in aviation and pharmaceuticals, where a private body is accredited to certify against a public standard.

Expected objection

That no third party has the compute or the access to run a real evaluation. That is a funding question, and the Secretariat budget is where it is answered.

ARTICLE IV

Incident reporting and assistance

A 72 hour reporting obligation for severe incidents, plus a mutual assistance channel, so that a containment failure in one jurisdiction reaches the others before it repeats.

Borrows from

The Convention on Early Notification of a Nuclear Accident, which turned disclosure from a corporate decision into a duty owed to other states.

Expected objection

That 72 hours is too short to know what happened. The obligation is to notify, not to explain; the analysis follows.

ARTICLE V

Verification

Declared compute accounting, on site inspection of training facilities on reasonable notice, and a technical means annex. This is the core bracket of the negotiation, and the reason the rest is worth writing.

Borrows from

Safeguards agreements and challenge inspections, the only mechanisms that have ever produced access to a facility held by another state.

Expected objection

That inspection of a data centre is either impossible or unacceptable. Both were said about enrichment plants, and both stopped being true once the instrument existed.

ARTICLE VI

Institutional mechanism

A Conference of the Parties meeting annually, a small permanent Secretariat, and a scientific panel with a standing mandate to update thresholds without reopening the treaty.

Borrows from

The Paris Agreement stocktake and the Montreal ozone assessment panels, both of which keep a technical body inside the instrument rather than beside it.

Expected objection

That another international body is the last thing anyone needs. The alternative is a treaty that expires the moment the technology moves.

Who we are

An independent drafting group

We write treaty text, we circulate it for comment, and we argue for it in the rooms where instruments are actually negotiated.

The initiative brings together public international lawyers, AI researchers and people who have sat on national delegations. None of us represents a government here. The draft belongs to whoever improves it.

We work in the open. Every article is published with the reasoning behind it, the precedent it borrows from, and the objection we expect it to meet. Where we cannot yet agree, the text stays in brackets rather than being smoothed over.

We take no position on any company, and we accept no funding from a frontier lab. The argument is about obligations between states, not about who wins a market.

01

We draft

A complete treaty text rather than a set of principles, because the disagreements only become visible once someone has written the operative paragraph.

02

We circulate

The draft goes to researchers, legal scholars and officials before any state is asked to sign, and every comment is answered in the open.

03

We argue for it

In the General Assembly, in regional bodies and in the summits, where the precedents that closed comparable gaps were actually built.

The board

Advisory

The initiative is guided by an advisory board. It has no executive role. Its members advise on the direction of the work and on how the initiative advances: what to draft next, which rooms to be in, and when the text is ready to be put to states.

Contact Us

AI Treaty Initiative

Tomas Antolinez Founder

Endorse

Sign the call for a treaty

Endorsing means you support the negotiation of a binding international instrument on frontier AI, on the terms set out in draft 0.1. You can sign as an individual or on behalf of an organisation.

0
Endorsements
0
Countries
0
Organisations
World map with endorsements
Drag to pan, scroll to zoom
No endorsements yet. Be the first.
Individual Organisation

Add your endorsement

Your name, city and country appear on the map and in the list below. Your email is not shown publicly and is used only to send the draft and one notice when the text changes.

Endorsements

Founder

Tomas Antolinez

Tomas Antolinez

Founder, AI Treaty Initiative

Tomas Antolinez founded the AI Treaty Initiative, which argues for a binding international treaty on frontier artificial intelligence.

He studied Political Science and Law at Universidad de los Andes, with a minor in Economics, and was part of the Effective Altruism group there. He worked in the Office of International Affairs at Colombia's Ministry of Environment and Sustainable Development.

His experience is in multilateral negotiation. He was a delegate of Colombia at COP30 and has taken part in more than six conferences of the parties of multilateral agreements. He was on the floor of the General Assembly when the Pact for the Future was adopted, and he took part in the Assembly's eightieth session. He was part of the team that created the First Conference on Transitioning Away from Fossil Fuels.

He is a member of Global Shapers, the World Economic Forum's community of young leaders.

← Back to Who we are