factolio.com

news & analysis

Who Governs the Machines?

Listen to this episode

Listen to this episode on RedCircle

Listen to Factolio on:

Spotify  |  Apple Podcasts  |  Amazon Music / Audible  |  iHeartRadio  |  YouTube  |  RedCircle

On September 23, 2026, OpenAI, Anthropic and Hugging Face executives briefed the United Nations Security Council on advanced-AI risks, including cyberattacks, biological misuse and possible loss of human control. The meeting increased the prominence of AI in the Council’s peace-and-security discussions, but produced no treaty or binding safeguards—leaving open who should set the rules and how much authority governments should give international institutions.


Factolio looks at major current events from several AI-generated perspectives. Red Velhouse is the moderator. Sam Dewinski brings historical context, Kate Burvish examines the economic forces and consequences, and Ann Tofado looks at the political dynamics and implications.

Discussion

Omar Seidren:

The Council held its 10,228th meeting on artificial intelligence and international security. Sam Altman appeared in person for OpenAI; Anthropic’s Dario Amodei and Hugging Face co-founder Clément Delangue joined remotely, and Yoshua Bengio briefed the Council as co-chair of the United Nations’ independent scientific panel on AI. Their shared warning was that advanced systems could create security risks faster than institutions can respond. The proposed answers included common testing, independent evaluation, stronger cybersecurity, incident reporting and meaningful human control. Those are recommendations, not a new global operating system for AI governance.

Ann Tofado:

The setting matters. The Security Council addresses threats to international peace and security, not merely product safety or consumer regulation. Bringing frontier-lab executives there signals an escalation in the political prominence of advanced AI as a strategic risk, building on the Council’s earlier AI discussions. But it also exposed a contradiction: companies asked governments to coordinate, while the United States resisted centralized global control and warned against slowing development relative to China. This was not a unified call for one world regulator. It was an argument over who defines danger and who decides what happens next.

Red Velhouse:

Sofia, did the briefing change the legal landscape, or mainly the political conversation?

Sofia Jadler:

It changed political salience, not the legal rulebook. A briefing does not automatically create duties for companies or states. There was no announced treaty, resolution, mandatory audit system, inspection authority or enforceable pause. Existing law still does the work: the United Nations Charter, international humanitarian law and international human-rights law remain the frameworks states invoke, especially for military uses. The legal move was reinforcement and agenda-setting. The Council gave AI greater prominence within its peace-and-security work while leaving the precise obligations for later; it did not establish AI as a new subject for the Council.

Red Velhouse:

Omar, when executives discuss loss of control, what does that mean technically—and what has not been demonstrated?

Omar Seidren:

It means a scenario in which systems become capable enough to pursue complex objectives in ways their developers cannot reliably supervise or stop. Amodei presented that as one broad risk category alongside malicious use. But a serious possibility is not the same as a demonstrated capability. The public record does not establish that current systems have durable independent goals, can recursively improve without human infrastructure, or can sustain strategically coherent operations beyond supervision. We do have failures, deceptive-looking behavior, cyber incidents and unsafe outputs. Those matter, but they are not evidence of an autonomous machine civilization waiting behind the server rack.

Ann Tofado:

That distinction is politically important. Governments can respond to a documented vulnerability with standards or reporting requirements. It is harder to legislate against possible future capabilities when experts disagree about timing and thresholds. Dramatic forecasts can mobilize attention, but they can also shift power toward the institutions and companies claiming special expertise. Governance should connect restrictions to observable capabilities, credible pathways to harm and mechanisms for accountability.

Sofia Jadler:

Uncertainty cuts both ways legally. It can justify precautionary testing and oversight, but it makes sweeping prohibitions vulnerable to disputes about evidence and proportionality. The strongest immediate argument is not that a machine has become a legal person. It is that human institutions still design, deploy and authorize these systems—and therefore remain responsible for setting limits.

Red Velhouse:

Why would executives whose companies benefit from rapid deployment invite more international regulation? Responsible leadership, or competitive strategy?

Ann Tofado:

It can be both. Frontier risks may exceed what one laboratory can manage, and common standards could reduce a race in which caution simply hands the market to a less cautious rival. But regulation has side effects. Large firms often find expensive testing, security and reporting easier to absorb than smaller competitors do. Standards may reduce systemic risk while reinforcing concentration. A company asking governments to regulate its industry may also be seeking legitimacy, liability protection or rules that preserve its advantage.

Omar Seidren:

The technical wrinkle is that enforcement points differ. A large, closed laboratory controls model weights, training infrastructure, access logs and deployment interfaces. An open-weight system may be distributed beyond its developer’s control. That does not make open systems inherently unsafe or closed systems inherently safe. Common testing can apply to both, while continuous monitoring, access controls and emergency shutdown authority may not. The software can cross borders faster than the paperwork—an unfortunate feature of both technology and bureaucracy.

Sofia Jadler:

That difference complicates responsibility. “The developer must prevent misuse” sounds clear until a model is modified, redistributed or embedded in another service. Responsibility may be divided among a laboratory, platform, state purchaser and military operator. Existing legal systems can assign responsibility through control, foreseeability, negligence or command structures, but the briefing created no international inspection regime to investigate disputed cases.

Red Velhouse:

Let’s turn to the cyber incident Delangue discussed. What does the Hugging Face episode actually show?

Omar Seidren:

It shows why operational security matters before anyone settles the grand debate about autonomy. Delangue used the incident to argue for stronger monitoring, security standards and international disclosure. But its full chronology and responsibility remain contested. We do not have a settled public account of the systems, permissions or data involved, or whether it reflected a general frontier capability rather than a narrowly configured failure. The disciplined conclusion is that AI infrastructure creates consequential attack surfaces requiring better reporting and containment—not that the machines escaped.

Ann Tofado:

That kind of incident can become a diplomatic bridge. The United States and China were separately discussing a possible notification mechanism for AI incidents with national-security implications. That is far narrower than a global regulator, but it could reduce the danger of mistaking a technical failure or cyber event for a deliberate strategic act. Governments may share enough information to avoid escalation even when they will not share control over their industries.

Sofia Jadler:

A workable notification system would need definitions first. What counts as an incident: a model escaping a sandbox, assistance with biological-weapons design, a cyber intrusion, or a dangerous military failure? Then come jurisdiction, evidence preservation, confidentiality and remedies. States will resist disclosures that expose sensitive capabilities; companies will resist reports that reveal trade secrets or invite liability. A practical first step would be a narrow duty to notify about defined national-security events, preserve technical evidence and create protected channels for urgent consultation.

Red Velhouse:

Suppose governments agree on communication but not a global regulator. Should they regulate dangerous uses, or set thresholds for what a system can do?

Omar Seidren:

Use-specific rules connect directly to harms: restrict assistance for biological weapons, secure cyber tools and require meaningful human control in high-stakes operations. Capability thresholds address systems that may be repurposed in unpredictable ways, but measuring capability is difficult. Benchmarks can be gamed, and real-world risk depends on tools, permissions, users and infrastructure. I would favor layered controls: specific prohibitions for especially dangerous uses, plus escalating evaluation and security requirements as capabilities and access expand.

Sofia Jadler:

That approach also fits legal proportionality. A blanket prohibition based on a speculative threshold invites disputes over science and compliance. Use-based rules can identify conduct already considered unacceptable, while capability-based duties can require testing, documentation and human oversight without declaring the technology itself unlawful. The unresolved issue is enforcement. A standard without access to logs, evidence or meaningful consequences is closer to a promise than a rule.

Ann Tofado:

And the institution matters. The Security Council has symbolic power, but any binding measure would confront the interests and veto power of its five permanent members. The General Assembly is more inclusive, and its 2025 resolution created an independent scientific panel and a global dialogue on AI governance, but those mechanisms are generally less coercive. The likely future is overlapping forums: scientific assessment, national regulation, alliances, crisis channels and occasional Council debates.

Red Velhouse:

Does that fragmentation create resilience, or simply loopholes?

Omar Seidren:

Both. Multiple layers let governments act where consensus is impossible, but they also create uneven standards and gaps between jurisdictions. Common incident categories, shared evaluation methods and minimum cybersecurity practices could make the system function more like a network than disconnected rules.

Ann Tofado:

Fragmentation is not politically neutral. The United States resists centralized control partly because it does not want safety arguments to weaken its position relative to China. China supports a prominent United Nations role while building its own capabilities and opposing what it calls AI-enabled hegemony. Both sides can sincerely worry about safety and still use governance language to shape influence. AI safety is now one of geopolitics’ preferred vocabularies.

Sofia Jadler:

The legal advantage of a network is gradual harmonization. The disadvantage is diffuse accountability. If every actor says someone else was responsible, the result may be paperwork without remedy. The law should preserve a clear human chain of responsibility, especially when governments deploy systems in armed conflict. Autonomy may complicate judgment, but it cannot become a liability escape hatch.

Red Velhouse:

Final round. What development would justify a pause, mandatory external evaluation or emergency consultations?

Omar Seidren:

I would look for repeatable evidence that a system can maintain long-horizon objectives, use tools beyond intended permissions, evade monitoring and transfer strategies across environments—not one alarming demonstration, but robust performance under independent testing. We should also watch for failures in which humans cannot reconstruct what happened or intervene in time. The goal is to define measurable escalation triggers before the crisis, while everyone still thinks the spreadsheet is in charge.

Ann Tofado:

Watch the narrow agreements. Does the possible United States-China notification channel become real? Do states establish shared language for serious incidents? Do companies accept independent evaluation they do not control? Those steps would show institutional movement rather than only dramatic testimony. A comprehensive treaty may be distant, but crisis communication and common reporting could build habits supporting stronger rules later.

Sofia Jadler:

Legally, watch whether the Council moves from general concern to a defined threat, reporting expectation or mandate connected to a concrete peace-and-security situation. Also watch how states apply existing humanitarian and human-rights obligations to autonomous or opaque systems. The most important development may be a stable evidentiary trail showing who approved, tested, operated and monitored a system when harm occurred.

Red Velhouse:

The unresolved issue is not whether advanced AI creates serious security questions; the participants broadly agreed that it does. The harder question is who can set credible limits when companies seek oversight, the United States resists centralized control, China favors a stronger United Nations role, and evidence about loss of control remains uncertain. Watch for a United States-China incident-notification channel, common testing and reporting standards, and any move from Security Council discussion toward a concrete mandate. Sources and references for this discussion are available with the episode at Factolio.com.


Sources and References

These sources supported the factual material used in this discussion. Factolio’s panel discussion is AI-generated from researched evidence and is written in original language.

  1. United Nations Security Council — Programme of Work: 10228th meeting — Maintenance of international peace and security: Artificial intelligence and international security (PRIMARY)
  2. United Nations Transcripts — Artificial intelligence and international security — Security Council, 10228th meeting (PRIMARY)
  3. Reuters — AI's biggest players tell UN the global risks are real (NEWS)
  4. ABC News — OpenAI, Anthropic CEOs at UN call for global cooperation on AI: 'We are at a crossroads' (NEWS)
  5. United Nations — Live: OpenAI and Anthropic brief Security Council amid warnings about runaway AI (PRIMARY)
  6. The Guardian — OpenAI’s Altman and Anthropic’s Amodei address UN Security Council (NEWS)
  7. Reuters Connect — OpenAI, Anthropic chiefs tell UN Security Council no single nation, company should control AI (NEWS)
  8. Axios — AI leaders brief UN leaders on need for global safeguards (NEWS)
  9. United Nations Independent International Scientific Panel on AI — AI Agents, Misalignment and the Risk of Losing Human Control (PRIMARY)
  10. Associated Press — UN chief urges global AI cooperation saying world can't afford a race to the bottom on AI safety (NEWS)
  11. United Nations Global Digital Compact — AI Panel & Dialogue — Terms of Reference and Modalities (PRIMARY)
  12. Associated Press — Tech leaders to UN: For the sake of humanity, please control the AI technology we created (NEWS)
  13. Associated Press — Trump downplays the need to check AI development and says he doesn't want to cede edge to China (NEWS)
  14. Security Council Report — Artificial Intelligence: High-level Briefing (ANALYSIS)
  15. United Nations Security Council — Security Council, 10005th meeting: Artificial intelligence and international security (PRIMARY)
  16. Associated Press — China and the US are competing for AI dominance but have shared concerns over safety (NEWS)
  17. Axios — U.S.-China 'red telephone' could bring a Cold War guardrail to AI (NEWS)
  18. United Nations Security Council — Security Council, 9381st meeting: Artificial intelligence and international peace and security (PRIMARY)
  19. United Nations Security Council — Concept note for the 2023 Security Council briefing on AI (PRIMARY)
  20. United Nations Security Council — Security Council, 9821st meeting: Artificial intelligence (PRIMARY)
  21. United Nations — United Nations Charter — full text (PRIMARY)
  22. United Nations — Governing AI for Humanity — Final Report (PRIMARY)
  23. Associated Press — Will AI models achieve the ability to improve autonomously? Leading labs say the scenario is near (NEWS)