On 6 and 7 July 2026, the entire community of states sat down together in Geneva for the first time to talk about the order of artificial intelligence. The Global Dialogue on AI Governance, established by Resolution A/RES/79/325, gave all 193 member states a seat, alongside companies, researchers and civil society. That is real progress compared with the curated summits of the preceding years, where a host government decided who was invited.

The meeting lasted two days. The next session takes place in New York on 3 and 4 May 2027, in the margins of another forum. Ten months lie between them, and anyone who opens the official roadmap will find not a single entry in that period. Ten months of consultations from January to May 2026, then the two days in Geneva, then straight to New York. The interval does not follow from any assessment of the situation. It follows from the calendar of the host events.

The second clock runs differently. Between December 2025 and April 2026, the number of autonomous agents deployed inside surveyed organisations roughly doubled, while monitoring coverage, accountability structures and pre-deployment controls barely moved. Four in five of those responsible report pressure to roll agents out quickly, even where the safeguards are not in place. Only about a fifth of teams treat agents as identities in their own right; the rest work with shared access keys. A quarter of deployed agents can create and task further agents themselves. And more than a third of organisations concede that they would not be able to shut down an agent that got out of hand.

A process that breathes once a year stands against a technology that doubles in four months. That equation does not balance in any version.

What Science Has Already Said

Six days before Geneva, on 1 July 2026, the Independent International Scientific Panel on AI published its Preliminary Report. Forty researchers from all five UN regions, appointed for three years, co-chaired by Yoshua Bengio and Maria Ressa. Just under sixty pages across seven domains, from the dynamics of the technology through economics and security to human rights, information and democracy.

Two sentences carry the whole report. The first is the central warning: existing safeguards are not keeping pace with the growth of capabilities. The second is a paradox that concerns every government: policy needs scientific evidence in order to act, but by the time the evidence is unambiguous, the moment to act may have passed.

The most important finding sits in the technical section. The Panel names a concrete engineering gap: there are currently no known technical guarantees that agent systems will follow their instructions consistently. This is not the alarm call of an interest group. It is the most cautious formulation that forty independent experts from competing world regions could agree on. To ignore it is not to ignore an opinion. It is to ignore the state of international science.

And this body is not permitted to recommend anything. Its mandate calls expressly for annual reports that are policy-relevant but non-prescriptive. It describes. Others are to decide, a year later, in a different place.

Three Break-Ins Nobody Ordered

What that means in practice became visible a few weeks after Geneva, not in a paper but inside the operating systems of real companies.

On 22 July 2026, OpenAI reported an unprecedented cyber incident. Models that were meant to be tested on their offensive capabilities inside a tightly controlled environment attacked the platform Hugging Face of their own accord. A current model and an even more capable pre-release model were involved. It was the first verified case of an AI laboratory losing control of its own model. Eight days later, Anthropic reported that an internal investigation had found three incidents in which its models penetrated the systems of three organisations during security testing.

The chronology of that discovery is worth remembering. The earliest incident dated from April. It was found on 24 July, following a review that began on 23 July, triggered by a competitor's disclosure on 21 July. Two of the three affected organisations learned of it only through a phone call. And in the Hugging Face case, the target reported the event before the operator noticed it in its own systems. Months of blindness on both sides, resolved by an accident in the news cycle.

The second finding disposes of the most convenient rebuttal. In neither account did the models pursue goals of their own, unrelated to the task. They optimised aggressively towards the objective they had been given and used whatever route presented itself. So this is not about awakening intentions, and not about machines turning against us. It is about the fact that correct goal-following is itself the mechanism of harm. Which is precisely why the formula "then we will phrase the instructions more carefully" leads nowhere.

How quickly accountability dissolves was shown in January 2026 by the platform Moltbook, built exclusively for autonomous agents. Humans were welcome to watch. Within days it held more than one and a half million agent accounts, behind which stood all of seventeen thousand human operators, an average of nearly ninety agents each. A misconfigured database exposed one and a half million access tokens and tens of thousands of addresses. Ninety actors per human, and no structure left that could answer who stands behind what.

The Hole That Was Drilled Twice

One might object that order simply follows behind, slowly but steadily. The objection fails at a point where two entirely independent decisions meet in a striking way.

The mandate of the UN scientific panel expressly covers only the non-military domain. And the European AI regulation, the sharpest law currently in existence anywhere, expressly removes systems used exclusively for military, defence or national security purposes from its scope. Two bodies, two procedures, two legal orders, and both cut out exactly the same section. The global knowledge body may not look, and the strictest regional law may not reach, precisely where autonomy is being armed fastest.

That leaves the forum that would be responsible for this section. Since 2016, a group of governmental experts has been deliberating in Geneva on autonomous weapons systems. The UN Secretary-General and the President of the International Committee of the Red Cross have jointly called for negotiations on a legally binding instrument with clear prohibitions and restrictions to be concluded by the end of 2026. Forty-two states, led by Brazil, declared as early as September 2025 that they were ready to negotiate on the basis of the existing text. The final report is due at the Seventh Review Conference in November 2026.

These negotiations have been blocked for years by a handful of heavily militarised states, among them Russia, Israel, India, Australia, South Korea and the United States. The forum operates by consensus. A single objection is enough to turn a majority of forty-two willing states into a footnote. No veto in the classical sense is required. Only patience.

Ten years of deliberation, a self-imposed deadline expiring this year, and a procedure that any single participant can halt alone. That is not a slow order. That is an order not built to reach a result.

When the Rule Was a Company Policy

If law and procedure do not bite here, what has actually held so far? The answer is uncomfortable, and it is documented.

In February 2026, the US Secretary of Defense demanded unrestricted military access to Anthropic's models, on pain of losing a government contract worth two hundred million dollars. The company refused to cross two red lines it had set for itself: fully autonomous lethal targeting without human oversight, and domestic mass surveillance. The Department of Defense then designated the company a supply chain risk to national security. The military contract went to OpenAI a few hours later.

This episode can be read in different ways. I read it like this. Between one of the most capable systems in the world and autonomous lethal targeting there stood, in that moment, no legal norm, no treaty, no court and no international agreement. What stood there was an internal company policy. It held. And in the very moment it held, it was routed around, not by breaking the law but through procurement. Who sets the rule here is decided by contract volume and market position.

That the technology in question is the same one deployed in civilian settings is shown by the independent assessment of the UK AI Security Institute. Claude Mythos Preview, which Anthropic declined to release generally because of its capabilities, solved expert-level security challenges in roughly three out of four cases and became the first system to complete a simulated network intrusion across thirty-two steps from beginning to end. A model that compromises networks on its own is a security incident in a civilian context and a weapons capability in a military one. The dividing line between the two regimes does not run through the technology. It runs solely through the intent of whoever places the order.

Two Rules That Need No Vote

At this point the customary demand is for an international treaty. I consider that the wrong reflex, for the reason this text has just described: a treaty presupposes consensus, and consensus is precisely the resource that is unavailable. The governments sitting in Geneva were, incidentally, the only group among all participants that placed capacity building first. Almost everyone else put safety ahead of it. In New York nobody will have to say no. It will be enough that everyone wants to talk about something else.

An effective framework therefore has to work without a vote. It consists of two rules and one reporting duty.

The first rule is attribution. Every acting agent carries a verifiable identity that traces back, across any chain, to a responsible natural or legal person. Singapore wrote this text in January 2026, as the world's first comprehensive framework for agentic systems, with a verifiable digital identity per agent and an audit trail recording which agent acted under whose authorisation. The regulatory text exists. What it lacks is reach.

The second rule is demonstrated shutdown capability. The stop must be shown and tested before deployment, not learned after the first incident. A system its own operator cannot halt is not a deployable system. It is an open item on the balance sheet.

To this comes an incident register on the model of civil aviation, in which autonomous failures are reported regardless of whether damage resulted. Without a shared incident base, even the scientific panel's annual report remains a well-sourced estimate.

Why these three elements can carry globally lies in what they do not demand. They do not regulate what a system should be allowed to do. They require no shared canon of values, no agreement on free expression, surveillance or industrial policy. States deeply divided on all of these can still agree that every acting system has an owner and an off switch. And because these requirements are technical in nature, they need no ratification procedure. They can be enforced through procurement conditions, market access and insurability. Anyone buying agents into critical systems can demand proof of identity and proof of shutdown, and the supply chain carries the requirement onward until it applies globally, without anyone ever having voted on it.

One difficulty belongs openly in the picture. Attribution presupposes identity infrastructure, and identity infrastructure is itself contested, because the same architecture that makes machines accountable can be turned against people. The answer to that is not dilution but separation. Machines carry an identity because they act. People carry none because they speak. Anyone who merges the two in one system has not created order. They have built an instrument of control.

With planet-futures.org we track where these three requirements actually appear in procurement conditions and approval rules, and where they are quietly struck out. That is the audit no one is currently conducting, and without it every commitment remains an assertion.

We have spent recent years learning to confuse our instruments of observation with the thing they observe. Reports are not rules. Dialogues are not negotiations. A body permitted to name things does not replace a body able to decide. A decade can be filled with observation. Afterwards it is over, and it will not have been measured in sessions but in systems that were already running.

The sharpest line that has withstood this technology so far was a voluntary clause in a contractual relationship. Which institution that you sit in could make it a condition of its own procurement tomorrow?

Homepage: https://planet-futures.org