1 · Concept overview
Existential risk governance means the institutional machinery that exists to prevent a catastrophe severe enough to end or permanently curtail civilisation, as distinct from the machinery for surviving one. In practice that is a short and specific list: verification regimes for weapons nobody is allowed to have, treaty bodies for weapons everybody has agreed to limit, oversight frameworks for research that could start a pandemic, statutes and evaluation bodies aimed at frontier artificial intelligence, a pandemic instrument negotiated after COVID, and two advisory groups for asteroids. This brief asks what each of those bodies is, what it can compel, what it has actually done, and whether any of it has ever been shown to work.
The answer to the last question is the organising fact of the brief and it should be stated at the top rather than saved for the end. Nothing in this subject has an independently measured counterfactual. What exists instead is detection events, self-reported throughput statistics from the bodies being assessed, and a negative existence claim whose denominator is unobservable. That is not an accusation of failure; it is a description of the evidence base, and it is the same shape the neighbouring slot found in a completely different literature.
The boundary against Civilization Resilience Planning, stated in both directions. That brief covers continuity and recovery — food reserves, seed vaults, what is left and how it rebuilds. This one covers prevention and control. Neither subsumes the other, and the collision check scored them at 17.1 hits per 10,000 words, which is a real overlap rather than a term artefact. Three places they genuinely interlock, named so the seam is visible: the 2022 United States statute usually cited as existential-risk legislation sits under an emergency management agency and its operative deliverables are a response annex and an exercise, which is continuity machinery wearing a prevention label; a 2021 House of Lords inquiry explicitly recommended abandoning prevention framing for resilience framing, a documented institutional choice against this brief's premise; and in 2025 a verification regime's integrity was broken not by treaty failure but by the physical destruction of the objects being verified, at which point the question becomes a recovery question.
Three further boundaries, because this slot sits in a crowded neighbourhood. AI Governance owns the measurement problem inside AI regulation — whether evaluation science can answer is this model dangerous, why the statutory trigger is a quantity of arithmetic, and the budget asymmetry between evaluators and the training runs they assess. This brief takes AI institutions only as members of the prevention-institution family and asks whether they have the features that separate the regime which works from the one which does not. Planetary Defense owns the deflection physics, the density conditional on DART's momentum enhancement and the survey shortfall; this brief owns only the governance layer above it, which turns out to be much weaker than the technology. And Civilizational Planning owns the one measured long-horizon success in the whole literature, the Montreal Protocol, along with the evaluation record of government foresight. That brief and this one reached the same verdict on measurement from disjoint evidence, which is worth more than either reaching it alone.
2 · Current scientific position
Established The Biological Weapons Convention prohibits an entire class of weapon of mass destruction and is administered by four people on a budget of about two million dollars. The Implementation Support Unit was established after the 2006 Review Conference with three permanent staff in Geneva; the Ninth Review Conference in December 2022 agreed to increase it from three persons to four for 2023–2027. The Convention's annual budget is given as $1.8 million by the Arms Control Association and as $2.1 million (€1.9 million) in 2023 by a survey in the Bulletin of the Atomic Scientists. That is the complete permanent apparatus of a treaty in force since 26 March 1975.
Established The comparison is what makes the number mean something, and it is roughly eighty to one. In the same survey, the OPCW spent $32 million (€30.3 million) on chemical-weapons verification in 2022 and the IAEA allocated $166 million (€153.7 million) to nuclear verification. The OPCW carries over 500 staff against the BWC's four. So the nuclear regime spends about eighty times what the biological one does on verification and the chemical regime about fifteen times; the arithmetic is this brief's and the inputs are sourced. The structural absences follow directly: no mandatory verified declarations of biological facilities, no inspections or site visits, no standing independent monitoring or challenge-inspection mechanism, and no dedicated international organisation of the kind the OPCW is for chemical weapons.
Frontier Even the membership count is contested, which is a small fact that says something larger. The Arms Control Association factsheet gives 187 states parties, four signatories and six states outside entirely; a reference handbook fetched the same day gives 189. This brief does not resolve it and reports the range, because a subject in which the headline membership of the flagship treaty differs by two between two current sources is a subject where nobody is checking.
Established The verification protocol died in July 2001 and the process that replaced it is scheduled to still be running in 2031. The Ad Hoc Group negotiated from January 1995 to July 2001 toward facility declarations and on-site inspections; the United States rejected the draft and any further negotiation, citing national security and commercial concerns. The consequence, in the phrasing of a UNIDIR-affiliated author writing in 2024, is that world governments then “have not discussed this topic within the treaty framework for two decades.” The Ninth Review Conference restarted something in December 2022: a working group meeting 15 days a year from 2023 to 2026, reporting to a Tenth Review Conference no later than 2027. But its own draft report proposes an Open-Ended Working Group on Compliance and Verification with work time allocated through 2031 and a report going “to States Parties for their consideration at the Eleventh Review Conference, or earlier at a Special Conference.” Not the Tenth. The Eleventh.
Established And the vetoes rotate, which is why this reads as stasis rather than as opposition. The United States killed the protocol in 2001. Russia blocked consensus on the article-by-article review in December 2022 over proposals about laboratories in Ukraine, at which point the American delegation walked out of the room. Russia blocked the working group's fifth session on its final evening, 13 December 2024, rejecting provisional cooperation and science mechanisms on a mandate-sequencing argument that, in the reporting NGO's words, “no other state supported” — costing a planned 2025 special conference and eleven months of accumulated agreement. In August 2026 Russia and Iran filed formal objections on verification language while the United States objected to letting the European Union contribute to an international-cooperation trust fund, a position observers described as an unexplained shift. Four blocks, three states, four different subjects. No institutional design survives that, and treating twenty-five years of stasis as a design problem misdiagnoses it.
Frontier What the working group has produced is a percentage, and the residue is the entire subject. By the second day of the August 2026 session the group had agreed 90.6% of its draft report text. The three topics the Chair set aside to get there were economic sanctions as a compliance tool, the decision procedures of the proposed new bodies, and the authority of the annual Meeting of States Parties — enforcement, governance and standing. The draft is still bracketed over whether to add “[three]” more secretariat posts and over whether the new body decides “by consensus”.
Established Safeguards on nuclear material is the regime that demonstrably works, and the qualifier is load-bearing. In 2025 it applied to 190 states, over 1,300 facilities, more than 3,000 in-field verification activities and 240,530 significant quantities of nuclear material under accountancy. Frontier But the conclusion an existential-risk brief actually cares about — that a state has no undeclared programme — was drawn for only 75 of 190 states, under 40%. The European Union's statement to the Board of Governors on 10 June 2025 independently confirms the number, recording that a broader conclusion for Morocco brought “the total number of such conclusions to 75” with 61 further states holding both a comprehensive safeguards agreement and an Additional Protocol where “the evaluation process is still ongoing”.
Established And the reason is a legal instrument, not a technical limit, which is the most transferable finding in this brief. The Agency's own account of the distinction is explicit: the narrower conclusion is that there is no indication of diversion of declared material; the broader conclusion additionally requires no indication of undeclared material or activities anywhere in the state, and it cannot be drawn at all unless an Additional Protocol is in force alongside the comprehensive safeguards agreement. Better inspectors, more money and improved technique do not get a state to the broader conclusion. A signature does. What separates the regime that works from the regime that does not is not competence or budget; it is a right of access written into law.
Established The strategic-arms architecture is now empty, and its verification died six years before its limits did. New START was signed 8 April 2010, entered into force 5 February 2011, was extended on 3 February 2021 and expired on 5 February 2026 with no successor. Its limits were 1,550 deployed strategic warheads, 700 deployed delivery vehicles and 800 deployed and non-deployed launchers, policed by 18 annual short-notice on-site inspections. Inspections stopped in 2020 for pandemic reasons and never resumed. Russia suspended participation on 21 February 2023 and discontinued notifications on 29 March 2023; the United States revoked Russian inspectors' visas on 2 June 2023. The last data exchange is dated 1 September 2022 — Russia at 540 deployed launchers and 1,549 deployed warheads, the United States at 659 and 1,420. So the last verified numbers are four years old and the last inspection six. Reporting February 2026 as the moment verification was lost gets the causal story backwards.
Frontier The endgame was an offer without verification, and whether it was refused or merely ignored is genuinely unclear. On 22 September 2025 Putin proposed that both states observe the central quantitative and qualitative limits for one further year, to 5 February 2027, conditional on reciprocity. He did not offer to restore inspections, data exchange or notifications, and two independent commentaries note the omission. Trump called the idea “good” in October 2025 and in January 2026 said that “if it expires, it expires”. A think-tank account by a former negotiator states that Washington rejected the offer; an advocacy factsheet and a disarmament centre record only that the United States did not respond. This brief does not resolve which it was, and the difference matters: a rejection is a policy, a non-response is a vacancy.
Frontier Cutting against the framing of institutional decay: an entirely new class of prevention institution appeared in about three years, and it has no powers. The International Network of AI Safety Institutes launched at the AI Seoul Summit in May 2024 with nine countries plus the European Union, first convening technically in San Francisco on 21–22 November 2024. Budgets are real — roughly £50 million ($65 million) a year for the United Kingdom institute, a $47.7 million United States request for FY2025, C$50 million pledged by Canada, and about $10 million elsewhere — and typical staffing is 20 to 30 technical people, with the European AI Office safety unit projected around 50. But the founding Seoul Statement is non-binding and “does not define specific goals or mechanisms”; the network has no formal legal authority; and it runs on “a horizontal leadership and consensus or opt-in only voting structure by default,” which the assessing think tank says “can make it challenging to take meaningful collective action.” On 4 June 2025 the network's anchor member had the word safety removed from its name and became the Center for AI Standards and Innovation.
3 · Frontier questions
The genuinely open questions in this subject are not about which risks are real. They are about whether an institution can be built that binds a party which does not want to be bound, and about whether anyone can tell afterwards that it worked. Those two questions are separable and the second is the harder one.
Frontier The first open question is whether biological verification is technically possible at all, and the disagreement is substantive rather than merely political. Russia and China favour routine on-site industry inspections, and the argument that this is operationally feasible is strong: the IAEA conducted 2,975 missions in 2022 and the OPCW ran 241 facility inspections a year before the pandemic. The United States doubts it, on the scale of the surface to be covered — in 2022 alone, 17,000 institutions worldwide published papers on biology and more than 15,000 unique applicants filed biotechnology-related patents. And there is a physical argument that has nothing to do with either position: because the agents self-replicate, “an agent amount at or below a threshold could be exceeded within a matter of hours.” A declaration threshold in a chemical regime describes a stock; in a biological regime it describes a starting point. This brief does not adjudicate the dispute and records that it is a real technical disagreement, not a proxy for a political one.
Frontier The second is whether the working group's proposed machinery is an institution or a schedule. Its draft would create an International Cooperation and Assistance Mechanism with a 20-member steering group, a Science and Technology Advisory Mechanism with a 25-member reporting committee, and an Open-Ended Working Group charged to “develop recommendations for concrete compliance and verification measures, including possible legally-binding measures”, examining “on-site and off-site approaches to verification that are practicable, feasible, effective, cost-effective and complementary.” That is the right mandate. It is also a mandate to recommend, with unspecified session counts, unspecified first-meeting dates and a bracketed decision rule, reporting to a review conference in the 2030s.
Established Dual-use research oversight has the best outturn evidence in this subject, and it points the opposite way from the usual framing. A supreme audit institution reports that NIH officials stated the agency supported “approximately 200 to 300 proposals and projects involving the specified select agents and toxins subject to dual use research of concern policies from December 2017 to June 2024” — annually. Against that, the administering office's own website as of July 2025 records exactly four projects referred for department-level P3CO review since 2018: three modified or with elements removed to become fundable, one unfunded. The Food and Drug Administration denied funding or approval to no extramural or intramural pathogen project on risk grounds. Frontier The ratio is a proxy rather than a measurement, because the categories are not coextensive and most select-agent work should never reach departmental referral. It is also the only ratio anyone has published, and a framework that referred four things in seven years cannot be characterised as a governance system on the available evidence.
Established The sharpest recent failure was caused by building institutions, not by their absence. The 2024 oversight policy for dual-use research and pathogens with enhanced pandemic potential came with 84 pages of implementation guidance and a deliberate one-year runway to an effective date of 6 May 2025. Institutions spent that year converting laboratories to higher containment, rewriting protocols and building training. Executive Order 14292 was issued on 4 May 2025, one day before the policy took effect, rescinded it, imposed an immediate pause on federally funded research labelled dangerous gain-of-function, and gave the science office 120 days to produce a replacement. A peer-reviewed assessment in mSphere describes the result as a “policy vacuum” with “vague definitions, an abrupt 120-day policy development deadline, and politically charged rhetoric that could undermine trust,” and records laboratories considering “pausing or restructuring their programs.” The governance problem in 2025 was not permissiveness. It was churn.
Handwave And a decade of dual-use policy has never been evaluated for its effect on the research it governs. Nothing consulted for this brief measures what the 2014 funding pause, the 2017 framework, the 2024 policy or the 2025 order did to publication counts, grant flows or offshoring. The literature argues; it does not measure. A decade of restriction has been imposed and lifted, in both directions, on essentially no evidence.
Frontier The frontier-AI question that belongs here rather than in the sibling brief is whether a self-published policy can function as an accountability instrument. Two independent graders say no, in almost the same words, and both are sympathetic to the enterprise. A safety-advocacy organisation scored twelve providers against 65 weighted criteria and found a range of 8% to 34% with a median of 18%, against a “peer ceiling” of 51% achievable from practices already in use somewhere in the industry. All twelve score 0–10% on processes to detect novel risks; all score below 25% on defining risk tolerance, most using “subjective language (e.g. ‘severe’ or ‘acceptable’) that do not have measurable conditions”; loss-of-control mitigation has a median score of 6%. On oversight: 9 of 12 score zero on executive risk officers, 7 of 12 zero on internal audit, and “no Provider commits to non-interference with third-party findings” — all twelve at zero. The evaluation-methodology organisation that originated the frontier-policy concept reaches the same list of gaps from a different method: no enforcement mechanisms, no independent verification standard, no consequences for non-compliance, and metrics such as “meaningfully increase risk” that cannot be checked.
Frontier One documented breach is on record and it is worth naming because it is the only one. A provider “released Grok 4 without a model card despite committing in their Framework to share evaluation results,” and the same assessment records that “some commitments appear to have weakened over time, without clear justification.” One breach in a regime with no auditor is not a compliance record; it is a sample of what becomes visible without one.
Handwave What is not open, stated plainly because the field's rhetoric says otherwise. Nothing here waits on a research result. Verification is inspection and accountancy. Oversight is a review committee reading a protocol. Command and control is procedure. The frontier in this brief is entirely institutional, fiscal and legal, and any account that presents catastrophic-risk governance as awaiting a scientific advance has misplaced the constraint.
4 · Technological bottlenecks
Established The first bottleneck is the veto, and the vetoes rotate. One state killed the biological protocol in 2001. A different state blocked the article-by-article review in 2022 and derailed the working group in December 2024. In August 2026 two states filed formal objections on verification language while a third objected to letting a regional bloc contribute to the trust fund. Four blocks by three parties on four different subjects across twenty-five years. No institutional design survives that, and every proposal that treats the stasis as a drafting problem is answering a question the record does not pose.
Established The second is that the declared-facility assumption is the whole game. Safeguards verifies what a state has declared, superbly. Detecting what it has not declared is a different and much weaker capability, gated on a separate legal instrument, and it is the one that matters for catastrophic risk. Seventy-five states of one hundred and ninety is the precise measure of that gap, with sixty-one more in evaluation and the remainder unable to reach it at all.
Established The third is money, and it is small money. The safeguards system runs on roughly €168 million a year under an explicit zero-real-growth policy since 2020, while the Agency records workload rising year on year. The Biological Weapons Convention runs on €1.9 million. Whatever else is true of catastrophic-risk prevention, it is not that the sums under discussion are large. They are a rounding error against the programmes they exist to constrain.
Established The fourth is that oversight frameworks do not survive changes of administration, and the discontinuity costs more than the policy difference does. A comprehensive 84-page policy with a deliberate one-year runway was superseded one day before its effective date; the replacement was directed on a 120-day deadline; research was suspended in the interval. Institutions that had spent a year building to a standard were left with no standard at all. Continuity is a governance capability in its own right and nothing in this sector has it.
Frontier The fifth is the absence of any auditor for the newest regime. Frontier-AI safety frameworks are self-published, self-graded and self-updated. Two independent assessments find no enforcement mechanism, no independent verification standard, no consequence for non-compliance, and zero of twelve providers committing not to interfere with third-party findings. That is the same structural position the Biological Weapons Convention has occupied since 1975, reached in three years instead of fifty, and by a different route: declarations without inspection there, self-assessment without audit here.
Frontier The sixth is that a treaty can be adopted and still not exist. The Pandemic Agreement was adopted on 20 May 2025 by 124 votes to none with 11 abstentions. It cannot be signed — not ratified, signed — until a pathogen access and benefit-sharing annex is adopted by the World Health Assembly, and that annex has slipped from May 2026 to May 2027 or an earlier special session. Sixty ratifications are needed for entry into force and the count is necessarily zero. The bottleneck here is not political will in the ordinary sense; it is a sequencing condition written into the instrument itself.
Frontier The seventh is that the evidence base for the governable risks does not exist. A government-commissioned assessment records “little empirical evidence” for artificial-intelligence risk and “little evidence” for engineered-pandemic risk. The two risks with genuinely quantified probabilities — asteroid impact and supervolcanic eruption — are the two nobody governs. The inverse relationship between how well a risk is quantified and how much institutional machinery is pointed at it is the uncomfortable shape of the whole subject, and the next section takes it as an experimental question rather than an irony.
5 · Research dependencies
Established Nothing here waits on a research result. That is an unusual sentence in a frontier-research corpus and it is the correct one. Verification is inspection and accountancy; oversight is a review committee reading a protocol; command and control is procedure; asteroid warning is a telescope network and an email list. Every constraint in this brief is institutional, legal or fiscal.
Established What prevention waits on is four things, each of which is documented above. An inspectorate with a legal right of access — the single feature separating the regime whose broader conclusion covers 75 states from the regime with four staff and no agreed definition of verification, and, within the working regime, the single feature separating the states where the broader conclusion can be drawn from those where it cannot. Consensus among parties holding vetoes, which is what has actually held for twenty-five years while three states blocked four different things. A budget that tracks workload rather than a zero-real-growth cap. And continuity of an oversight framework across a change of administration, the absence of which produced a policy vacuum from a policy that had a year's runway.
Frontier One dependency is newer and is not usually listed: an auditor for self-published safety commitments. The frontier-AI regime has obligations, thresholds, capability definitions and internal governance structures, and no external body with a right to check any of it. Two independent gradings converge on the same missing element. Whether the European enforcement powers that opened in August 2026 supply it is the open question; a regulator with a fining power is not the same thing as an inspectorate with an access right, and this brief does not assume the one implies the other.
Established What depends on this brief runs mostly to its siblings. Civilization Resilience Planning inherits everything prevention fails to stop, which is why the two briefs share a seam rather than a boundary. Global Cooperation Models takes the same treaty bodies as instances of a general question about whether cooperation instruments change state behaviour. AI Governance depends on this brief only for the comparative frame — whether its institutions look like the ones that worked or the ones that did not. And Scientific Advisory Institutions supplies the advice all of these bodies act on, including the science and technology mechanism the biological working group is trying to create.
6 · Required experiments
Established The measurement that would change this field is the one the audit institution asked for and did not get. Publish oversight outcomes systematically: review counts, decisions, mitigation conditions, and the denominator of projects screened. The audit office recommended exactly this — that key information on risk reviews “are publicly shared with researchers, Congress, and the public”, including outcomes, mitigation steps and regularly updated aggregate counts. The department neither agreed nor disagreed. The data already exists and is already reported internally; the finding was that withholding it “do[es] not fully align with a key element of effective oversight — transparency.” It costs nothing to publish and its absence is why the only available effectiveness measure in the whole of dual-use governance is a ratio of four to two or three hundred.
Frontier Second, and genuinely tractable: evaluate the 2014 funding pause retrospectively. Publication and grant data for the affected research areas exist for 2014–2017 and after. Nobody has looked. A decade of policy argument — in both directions, by people who agree on nothing else — rests on an empirical question a competent bibliometrician could answer in months.
Frontier Third, the natural experiment now running in Geneva has a date and a readout. The working group's final four-day session was scheduled for December 2026 with 90.6% of a report text agreed and enforcement, decision rules and standing unresolved. If it reports to the 2027 Review Conference with a compliance and verification body that has a first meeting date, a session count and a decision rule that is not bracketed, the Convention has produced its first machinery since 2001. If it reports the current draft — an open-ended group running to 2031 and reporting to the Eleventh Review Conference — then the working group's function was to convert a deadlock into a timetable, and that should be recorded as the result rather than as a delay.
Frontier Fourth, the frontier-AI regime has a scheduled test of whether obligations without an auditor behave differently from obligations with one. European enforcement powers, including fines, become available on 2 August 2026, against general-purpose model obligations that have applied since 2 August 2025. That is a rare clean before-and-after: the same obligations, the same firms, a year of self-reporting followed by a regulator that can levy up to 3% of global turnover. Whether the self-published frameworks graded at a median of 18% improve after that date is measurable, and the graders have already published a baseline and a method.
Established Fifth, a negative result worth recording as an experiment in its own right: the arms-control counterfactual cannot be constructed and the serious literature says so. Kennedy predicted in 1963 that “15 or 20 or 25 nations may have these (nuclear) weapons” by the 1970s; four had them then and nine do now. One school — Nye, Walsh, Coe and Vaynman, Fuhrmann and Lupu — reads that as treaty effect through information transparency and domestic political empowerment, and points out that “no country has successfully been able to produce nuclear weapons while subject to the NPT and its safeguards.” Another — Betts, Solingen, Hymans — reads it as selection: states join because they already lack intent, so the correlation is screening. The decisive sentence is neither side's conclusion but the epistemic statement both must accept: “history does not provide us with a counterfactual world in which there was no NPT.”
Frontier Sixth, and the only design that would settle anything: a prevention institution with a control group. Nothing in this brief has one. The nearest available candidates are staggered adoption of the Additional Protocol across states, and the staggered establishment of national AI evaluation bodies across countries with otherwise comparable technology sectors. Both are natural experiments with real variation in timing, and neither appears to have been exploited. Until someone does, “the regime prevented proliferation” and “the regime selected non-proliferators” remain observationally equivalent, and so do the equivalent pairs for every other institution described here.
7 · Engineering requirements
Established The mechanism that separates a working verification regime from a symbolic one is a right of access written into a legal instrument, and it can be stated as a table. Four regimes, four levels of intrusiveness, and the correlation with demonstrated capability is exact.
| Regime | Access | Verification spend | What it can conclude |
|---|---|---|---|
| IAEA safeguards, comprehensive agreement only | Declared facilities, by right | €153.7 million (2022 figure, whole regime) | Declared material not diverted |
| IAEA safeguards, plus Additional Protocol | Declared and undeclared locations, by right | No undeclared material or activities — drawn for 75 states | |
| Chemical Weapons Convention (OPCW) | Routine and challenge inspection, by right | €30.3 million (2022); 241 facility inspections a year pre-pandemic | Declared facility compliance |
| Biological Weapons Convention | None. Voluntary declarations only | €1.9 million total budget (2023); four staff | Nothing. No compliance-review body exists |
Established Read the first two rows together, because they are the same organisation with the same inspectors and the same techniques. The only difference is whether a second legal instrument is in force. Without an Additional Protocol the Agency can conclude that declared material has not been diverted and cannot conclude anything about undeclared material, however competent its inspectors. That is the cleanest available demonstration that the binding variable in verification is legal access rather than capability, and it is why every proposal to fix the Biological Weapons Convention by improving its science reaches for the wrong lever.
Established The transparency instrument the Convention does have is a voluntary annual return, and participation has never approached universality. Six categories of confidence-building measure remain live, one having been deleted in 2011: military biological defence programmes, unusual disease outbreaks, encouragement of publication, national legislation and regulation, past offensive and defensive programmes, and vaccine production facilities. Frontier Participation figures do not agree between sources and this brief reports the range rather than picking one. The secretariat's own presentation gives 67 of 189 parties — 35% — for 2025, the best in the Convention's history, with 18% of parties never having submitted anything across 1987–2024. A reference handbook gives “approximately 50% of States Parties”. A specialist factsheet says the effort has been “largely unsuccessful; the vast majority of states-parties have consistently failed to submit declarations.” The common failure modes are agreed even where the numbers are not: incomplete submissions, inconsistent formats, and returns identical year to year.
Established The command-and-control design lessons are unglamorous and each was learned expensively. Separate test systems from operational ones physically: a 1979 false alarm displaying more than a thousand inbound missiles was a training tape loaded into the live system, and the remedy was a $16 million offsite facility. Assume component failure will be unreproducible — the 1980 sequence traced to a defective integrated circuit that could not be made to fail again under test. Frontier And build the human confirmation step to be fast enough to matter: the 1979 event was resolved in six to seven minutes, and the June 1980 alerts terminated after 32 and 17 minutes, in both cases after crews had already been moved.
Frontier The gap between declared posture and exercised capability is visible in the primary record. The current posture review states that while the capability to launch under attack is maintained, the United States “does not rely on a launch-under-attack policy”, and that further de-alerting “could undermine crisis stability”. The declassified 1980 memorandum records bomber crews reaching aircraft and starting engines within two minutes of a false indication. Not relying on a capability is not the same as not exercising it.
Established The AI statute's machinery is dates and thresholds rather than inspection, and the dates are the mechanism. General-purpose model obligations under the European regulation have applied since 2 August 2025; models placed on the market before that date must comply by 2 August 2027; and the Commission's enforcement powers, including the power to fine, become available on 2 August 2026 — a full year after the obligations attached. Penalty ceilings are €15 million or 3% of global turnover for high-risk violations and €35 million or 7% for prohibited practices. The indicative threshold for a general-purpose model in the Commission's guidance is 1023 floating-point operations of training compute combined with generative capability in language, image or audio. Why a compute threshold rather than a capability test is AI Governance's argument to make and is not restated here.
8 · Adjacent technologies
The nearest neighbour is Civilization Resilience Planning, and the relationship is a seam rather than a line. Everything prevention fails to stop arrives there, and one of the two risks with a real recurrence estimate — a VEI 7 volcanic eruption — has no prevention story at all, so it is entirely that brief's. The 2025 case in which a verification regime's integrity was destroyed by ordnance rather than by defection crosses the seam in mid-event.
Civilizational Planning is adjacent in the strongest analytical sense, because the two briefs converge on the same verdict from disjoint evidence. That brief found four official or peer-reviewed assessments of whether government foresight changes decisions, four findings of absent impact and zero counterfactual designs. This brief finds zero measured counterfactuals across every prevention institution it examines. Neither result would be worth much alone; together they describe a governance literature that has not been scored anywhere. That brief also owns the one measured long-horizon success in the field, the Montreal Protocol, which is why this brief does not re-argue it.
AI Governance is adjacent by division of labour. It owns the measurement problem inside the statute — the compute trigger, the evaluation science, the budget asymmetry. This brief owns only the comparative institutional question, and the comparison is unflattering in a specific way: the newest prevention regime has arrived, in three years, at the structural position the Biological Weapons Convention took fifty years to occupy.
Planetary Defense is adjacent as the counter-case, and the counter-case is narrower than it looks. It owns the deflection physics and the survey shortfall. What belongs here is that its governance layer — two advisory groups, twenty member agencies, a secretariat mandated with no financial implications for the United Nations budget, and no authority to launch anything — is the weakest in this brief, and the risk it governs is nonetheless the best handled. That inverts the usual lesson and is treated at length in the misconceptions below.
Global Cooperation Models takes these same treaty bodies as instances of a general question about whether cooperation instruments change what states do, and Scientific Advisory Institutions supplies the advice these bodies act on — including, if the biological working group's draft survives, a new 25-member science and technology reporting committee that would be exactly such an institution.
9 · Institutional requirements
Established The defining institutional asymmetry is between regimes with a legal right of access and regimes without one, and it cuts through the middle of a single organisation. The same agency, with the same inspectors and the same techniques, can conclude that no undeclared material or activity exists in a state where an Additional Protocol is in force and cannot conclude it in a state where one is not. Seventy-five states are in the first category, sixty-one are in evaluation, and the rest are not reachable at any budget. This is the most useful institutional fact in the brief because it is a controlled comparison: hold competence, technique and funding constant, vary only the legal instrument, and the regime's central capability appears or disappears.
Established Who pays, and how little. Nuclear verification runs at roughly €153.7–168 million a year under a zero-real-growth policy since 2020 against rising workload. Chemical verification runs at about €30.3 million with over 500 staff. Biological prohibition runs at €1.9 million with four. National AI evaluation bodies run between about $10 million and $65 million with 20 to 30 staff each. The entire global institutional apparatus for preventing weapon-of-mass-destruction and frontier-technology catastrophe costs less than a single large research facility, and considerably less than the training runs the newest of these bodies exists to assess.
Established Who regulates, and on what schedule. The European Union is now the only jurisdiction with binding, generally applicable obligations on frontier models: general-purpose obligations in force since 2 August 2025, enforcement powers including fines from 2 August 2026, penalty ceilings of €15 million or 3% and €35 million or 7% of global turnover, and a compute threshold of 1023 operations in the guidance. It is also a jurisdiction that has already deferred: high-risk obligations for standalone systems moved from 2 August 2026 to 2 December 2027 and for embedded systems from 2 August 2027 to 2 August 2028, and an AI-literacy duty was softened from a competence requirement to a duty to take “measures supporting” literacy. General-purpose obligations were not deferred. A regime that defers its first hard deadline before reaching it is a regime whose second deadline should be read as an intention.
Frontier The institution that exists and cannot decide. Planetary defence is governed by two bodies endorsed by the United Nations in June and December 2013 after a process beginning in 2000: an asteroid warning network with a steering committee of about ten, and a mission planning group with 20 member space agencies and seven observers, currently chaired by the European Space Agency, whose permanent secretariat was established by General Assembly resolution 71/90 in 2016 expressly “with no financial implications for the budget of the United Nations”. They meet twice a year. They have run observation campaigns on 2012 TC4, Apophis, Moshup and two timing targets, and they can distribute a warning “in a matter of hours or less”. They cannot authorise a mission. The recommendation goes, in the primary account's words, “to decision-makers — leaders of space agencies, national delegations, etc.”
Frontier The institution that was adopted and does not yet exist. The Pandemic Agreement has 124 affirmative votes, an explicit denial that the World Health Organization may “direct, order, alter or otherwise prescribe” national policy, twenty-six United States governors who declared in August 2024 that they would not comply, no signature process, and no ratifications, because a benefit-sharing annex that has been in negotiation through eight rounds must be adopted first. It is the purest available example of an institution that exists in the record and not in law.
Frontier The institution that does not exist at all is an external auditor of frontier-AI safety commitments. Twelve providers publish frameworks; nine of twelve have no executive risk officer commitment, seven of twelve no internal audit commitment, and none of the twelve commits to non-interference with third-party findings. There is no body with a right to check any of it, no standard against which to check, and no consequence for divergence. That is the same structural hole the Biological Weapons Convention has had since 1975, and the newest prevention regime in the world arrived at it in three years.
10 · Ethical & societal considerations
Established The distinctive ethical structure here is that the costs of prevention are certain and borne now, while the benefit is an event that does not happen. That asymmetry explains the observed pattern better than bad faith does: a framework that reviews four projects in seven years is what happens when a diffuse future benefit meets a concentrated present cost, repeatedly, in a budget process. It also explains why the two risks with the best-quantified probabilities attract the least machinery — a one-in-a-thousand-years event has no constituency in any electoral cycle.
Established The evidence problem is severe and this brief marks it rather than working around it. Almost every institution described here reports on itself. The treaty secretariat publishes the participation statistics for the transparency mechanism it administers. The health department publishes the throughput of the review framework it operates. The safeguards agency publishes its own implementation report. The AI providers publish their own safety frameworks and grade their own compliance. None of that is dishonest and all of it is interested. The genuinely independent evidence in this subject comes from three places and only three: supreme audit institutions, the declassified documentary record, and peer-reviewed work by authors with no stake in the institution.
Frontier And the interested parties are on both sides, which is the part most accounts get wrong. Risk-advocacy organisations are interested parties too. The clearest instance in this pass is a catastrophic-risk consultancy reporting a keynote figure for Pinatubo-scale cooling — a VEI 6 event — in a piece about VEI 7 risk, in a way that a reader would naturally carry across. The two frontier-AI gradings this brief relies on are both by organisations whose purpose is to raise AI risk up the agenda, and their findings are used here because they are specific, reproducible and grade against a published rubric — not because the graders are disinterested. Sceptical reading is owed in both directions, and a brief that applies it only to governments has taken a side without saying so.
Frontier The dual-use case makes the substantive conflict explicit and unresolved. Research that could characterise a pandemic pathogen well enough to defend against it is the same research that could create one, and the instruments deployed so far — a funding pause, a review framework, an executive order, a suspension — are blunt precisely because the distinction is not technical. Handwave That nobody has measured what any of them did to the research is not a neutral gap. It means a decade of restriction has been imposed and lifted, in both directions, on essentially no evidence, by people confident in both directions.
Established A disclosure this brief owes about its own evidence. The research pass behind this revision exhausted its search budget partway through, and twelve of the fifteen sources the previous version carried could not be re-opened. They are retained and they carry only the claims the previous version already made; no new claim rests on any of them. Two figures in particular are flagged rather than smoothed: the confidence-building-measure participation rate, where the secretariat's own 35% and a reference work's 50% cannot be reconciled, and the staff count of one national AI institute, which is that institute's self-description and sits awkwardly against an independent estimate of 20 to 30 for comparable bodies. Stating this is the alternative to a brief that looks more certain than its sources.
Frontier Four questions this brief cannot answer and will not pretend to. Whether any prevention institution has ever prevented anything — no counterfactual exists for any of them. Whether biological verification is technically achievable at all, on which Russia, China and the United States hold substantively different technical positions and this brief takes none. Whether the retreat from prevention to resilience is a correct judgement about tractability or an abdication. And whether a new institutional layer is on balance a constraint or a new veto point, given that two of the four failures documented here were produced by institution-building rather than by its absence.
11 · Civilizational implications
Established The civilisational reading is that prevention institutions are far weaker than their remits imply, and the weakness is fiscal, legal and political rather than conceptual. Four people administer a global prohibition on biological weapons on about €1.9 million a year. The one verification regime that works reaches its decisive conclusion for 75 of 190 states and is capped below its own workload growth for the sake of roughly €40 million. The strategic-arms limits lapsed in February 2026 and nothing replaced them, six years after their verification had already stopped. A pandemic instrument adopted by 124 states cannot be signed. None of these is a hard problem in the sense that fusion or protein folding is a hard problem; they are budget lines and signatures.
Frontier The general principle this case illustrates is that the object of governance determines whether governance is possible, and it does so more strongly than institutional design does. Safeguards works on material that can be weighed, in facilities that can be counted, under a legal instrument that grants access. Planetary defence works on objects that can be catalogued individually. Where the object is an intention, a protocol, a model weight or a pathogen a laboratory has not declared, no design supplies the countability that made the working regimes work. That is why the Biological Weapons Convention has no inspectorate — not because nobody proposed one, but because 17,000 institutions published biology papers in 2022 and the quantity that matters can be exceeded, in one specialist's phrase, “within a matter of hours.”
Frontier And there is a documented institutional retreat from prevention as a frame. A parliamentary inquiry recommended moving from attempting to forecast and mitigate discrete risks toward “a more holistic system of preparedness”; the statute most cited as existential-risk legislation delivers a response annex and an exercise. The drift is from stopping the event to surviving it — which is a defensible judgement about tractability and should be recognised as a choice rather than as a gap. Whether it is the right choice is Civilization Resilience Planning's question.
Handwave Accounts implying a coordinated global prevention architecture describe nothing that exists. There is no body with authority over more than one risk, no shared budget, no common evidentiary standard, and no institution anywhere whose effect has been measured against a counterfactual. What exists is four unrelated regimes with incompatible designs, three of which are administered by the parties they constrain.
12 · Timelines
Established What already happened, because the timeline usually starts too late. The Biological Weapons Convention entered into force on 26 March 1975 and has never had a verification mechanism. Its protocol was negotiated from January 1995 and rejected in July 2001. Its secretariat was created in 2006 with three staff and reached four in 2023. New START entered into force on 5 February 2011 and its inspections stopped in 2020. The dual-use review framework referred four projects between 2018 and July 2025. None of this is recent and none of it is trending.
Established 2025 to 2026, the interval in which four things happened at once. An executive order rescinded a dual-use policy one day before it took effect, on 4 May 2025. The Pandemic Agreement was adopted on 20 May 2025 and could not be signed. The United States AI Safety Institute was renamed on 4 June 2025. New START expired on 5 February 2026 with nothing in its place. Four prevention institutions moved in fifteen months and three of the four moves were backwards.
Frontier Late 2026: two scheduled readouts. The biological working group's final four-day session was set for December 2026, with 90.6% of a draft report agreed and enforcement unresolved. European enforcement powers over general-purpose AI models became available on 2 August 2026, a year after the obligations attached. Both are dates on which something either happens or visibly does not.
Frontier 2027: the Tenth Review Conference, and the year the Pandemic Agreement might open for signature. The review conference is mandated for no later than 2027. The pandemic annex goes to the World Health Assembly in May 2027 or an earlier special session; only after its adoption can any state sign, and only after sixty ratifications does the instrument enter into force. Handwave No date for entry into force can responsibly be given, because the ratification clock has not started and cannot start until the annex exists.
Frontier 2031: the biological compliance body's own horizon. The working group's draft allocates its proposed Open-Ended Working Group on Compliance and Verification work time through 2031, reporting to the Eleventh Review Conference or an earlier special conference. That is the first structured moment at which anything about biological verification could be decided, thirty years after the protocol was rejected.
Speculative The 2030s: the plausible split, stated as a hypothesis rather than a forecast. Regimes with a hard trade, supply or market instrument attached — safeguards, which gates nuclear commerce; the European AI statute, which gates market access — most plausibly persist and grow. Prohibition regimes with no such instrument most plausibly continue to run on voluntary declarations. Nothing in the record contradicts this and nothing tests it.
Handwave Beyond that, dates are not available and this brief declines to supply them. The structural problem — that prevention is verified by the parties it constrains, and that its output is a counterfactual nobody can observe — is not a technological one and has no horizon. Any timeline that assigns a date to “adequate global catastrophic-risk governance” is describing a wish.
Speculative Further out, prevention capacity most plausibly consolidates around the risks that are industrially legible — those requiring facilities, materials and supply chains that can be counted, inspected and denied. Risks requiring none of those remain governed by declaration. Everything in this brief points the same way: the nuclear regime spends roughly eighty times what the biological one does and inspects things that occupy buildings; the safeguards system cannot draw its strongest conclusion without a legal instrument in force, whatever its instruments can measure; and the one existential risk with a funded, technically successful institutional response is the one where the hazard is a trackable object in a catalogue. This is a hypothesis about which risks institutions can get purchase on, not a prediction about which risks matter, and the gap between those two is the uncomfortable part.
13 · Technology tree & dependencies
- Depends on Nothing on this map. No brief in this corpus produces a result that catastrophic-risk prevention is waiting for. Verification is inspection and accountancy, oversight is a committee, command and control is procedure, and asteroid warning is a telescope network. The constraints are institutional, legal and fiscal, and the useful consequence of saying so is that no amount of research progress elsewhere relieves any of them.
- Requires (not on this map) An inspectorate with a legal right of access. This is the single feature separating the regime that works from the one with four staff, and it operates inside the working regime too: the Additional Protocol is what lets the same inspectors with the same techniques conclude something about undeclared material, which is why 75 states have a broader conclusion and the rest do not. Consensus among parties holding vetoes, the constraint that has actually held for twenty-five years while three states blocked four different things. Oversight continuity across a change of administration, absent when an 84-page policy with a year's runway was superseded one day before taking effect. An external auditor for self-published safety commitments, which the frontier-AI regime lacks entirely — zero of twelve providers commit to non-interference with third-party findings. And a verification budget that tracks workload rather than a zero-real-growth cap, the gap being roughly €40 million against a €168 million base. All five are institutional or fiscal; none is a research result.
- Enables A civilisation that is still here. No typed enabling edge is claimed and the reason is worth stating rather than hiding: prevention's output is a counterfactual, so nothing on this map can be said to depend on it in a way an edge could carry. That is not a formatting concession. It is the brief's central epistemic problem showing up in the data model.
- Adjacent Civilization Resilience Planning, which inherits whatever prevention fails to stop; Global Cooperation Models, which treats compliance as a general institutional question; AI Governance, where the newest prevention institutions are being built; Planetary Defense, the one risk with a demonstrated countermeasure and the weakest governance layer in this brief; and Civilizational Planning, which reached the same verdict on measurement from an entirely different evidence base. Outside this map: arms control and non-proliferation law, biosafety and biosecurity practice, and the declassified documentary record, which is where the near-miss evidence actually lives.
14 · Common misconceptions & speculative claims
“The Biological Weapons Convention has three staff.” Established Half right and a year out of date, and the correction makes the fact stronger rather than weaker. It had three from 2007; the Ninth Review Conference in December 2022 agreed to increase the staff “from three persons to four for 2023–2027”, and a reference handbook records four professional staff as of 2025. The number to quote is not the headcount but the money: $2.1 million (€1.9 million) in 2023, against $32 million (€30.3 million) of OPCW verification spending in 2022 and $166 million (€153.7 million) of IAEA nuclear verification. The working group's current draft is still bracketed over whether to add “[three]” more posts.
“The 2022 Review Conference failed.” Established It failed at part of itself, and the part matters. The conference adopted a final document on 16 December 2022 and created a working group with fifteen days a year and a mandate covering compliance and verification — the first formal subsidiary body on that subject since 2001. What collapsed the previous day was Part II, the article-by-article review, over Russian proposals about laboratories in Ukraine. Both descriptions are true of the same fortnight, and accounts printing only one are half-reported rather than wrong.
“The working group is close to producing something for the 2027 review conference.” Established Its own draft says otherwise, and this is the correction the published record most needs. The proposed Open-Ended Working Group on Compliance and Verification is allocated work time through 2031 and its report goes “to States Parties for their consideration at the Eleventh Review Conference, or earlier at a Special Conference.” Not the Tenth. Ninety-point-six per cent of a report text is agreed and the residue is the whole subject: sanctions as a compliance tool, decision procedures for the new bodies, and the authority of the annual meeting.
“New START's expiry created a verification gap.” Established The verification gap opened in 2020 and the treaty expired in 2026. Inspections stopped for pandemic reasons and never resumed; notifications ended on 29 March 2023; the United States revoked inspector visas on 2 June 2023; and the last data exchange is dated 1 September 2022. What lapsed in February 2026 was the numerical limits, which had already been unverified for six years. This is the single most common framing error in current writing on nuclear arms control and it inverts the causal story.
“Russia and the United States agreed to keep observing the limits.” Frontier No. Putin proposed it on 22 September 2025, for one year, and explicitly did not offer to restore verification, data exchange or notifications — two independent commentaries note the omission. Trump called the idea “good” in October 2025 and in January 2026 said “if it expires, it expires”. Whether Washington rejected the offer or simply never answered is contested between the sources consulted here, and the difference matters: a rejection is a policy, a non-response is a vacancy.
“The Pandemic Agreement is in force” or “is being ratified.” Established Neither. It was adopted on 20 May 2025 by 124 votes to none with 11 abstentions, with the United States not participating, and it cannot be signed at all — not ratified, signed — until a pathogen access and benefit-sharing annex is adopted by the World Health Assembly. That annex missed its May 2026 deadline; a seventh round ended on 17 July 2026 with contractual arrangements, laboratory networks and the definition of benefits still open; an eighth ran 14–18 September 2026; the outcome goes to the Assembly in May 2027 or an earlier special session. Sixty ratifications are required and the count is necessarily zero.
“The 2014–2017 gain-of-function measure was a moratorium.” Established It was a national funding pause on a defined subset of work, with no prohibition on the research, no extraterritorial reach and no effect on private funding. “Moratorium” is the critics' word on both flanks and it materially overstates the instrument.
“The 2025 problem was that oversight was weakened.” Established The 2025 problem was that oversight briefly stopped existing. A comprehensive policy with 84 pages of implementation guidance and a deliberate one-year runway to 6 May 2025 was superseded by executive order on 4 May 2025, one day before it took effect, with a 120-day deadline for a replacement and research suspended in the interval. A peer-reviewed assessment calls the result a “policy vacuum” and records laboratories considering “pausing or restructuring their programs”. The failure mode was institutional churn, and it is the reverse of the failure mode the public debate anticipates.
“Dual-use oversight reviews hundreds of dangerous experiments.” Established Four, since 2018, at department level — three modified into acceptability and one unfunded — against approximately 200 to 300 select-agent proposals and projects a year. Frontier The categories are not coextensive and the ratio is a proxy, not a measurement. It is also the only published ratio, and when an audit office asked the department to publish the real denominators it already collects, the department neither agreed nor disagreed.
“Safeguards works.” Established In a specific sense, and the specificity is the finding. Material accountancy at declared facilities is excellent; the broader conclusion that a state has no undeclared programme was drawn for 75 of 190 states, and for eleven the Secretariat can draw no conclusion at all. The constraint is legal, not technical: the broader conclusion requires an Additional Protocol in force, and without one the same inspectors with the same techniques and budget cannot reach it.
“AI safety institutes are a new kind of regulator.” Frontier They are a new kind of evaluator: a non-binding founding statement, no formal legal authority, decisions by “horizontal leadership and consensus or opt-in only”, budgets from about $10 million to $65 million, typical staffing of 20 to 30, and an anchor member that had the word safety removed from its name on 4 June 2025. Established What cuts the other way, and belongs in any honest account: “no government body has an explicit catastrophic-capability remit” was true in 2022 and is false now.
“Voluntary frontier-AI commitments are working.” Frontier Two independent graders, both sympathetic to the enterprise and both interested parties, say the opposite in nearly identical terms. Twelve providers score 8% to 34% against 65 weighted criteria, median 18%, against a peer ceiling of 51% built only from practices already in industry use; all twelve score zero on committing not to interfere with third-party findings; loss-of-control mitigation has a median score of 6%. The other assessment's list of gaps matches: no enforcement mechanism, no verification standard, no consequence for non-compliance. One breach is documented — a model shipped without the model card its own framework promised — which in a regime with no auditor is a sample rather than a compliance record.
“DART proved that catastrophic-risk institutions can work.” Established DART proved a technique. The institutions around it were recommended by a process running from 2000, endorsed in June and December 2013, and consist of two advisory bodies that meet twice a year, run on a secretariat mandated “with no financial implications for the budget of the United Nations”, and cannot authorise a deflection mission. At the 2023 exercise the planning group recommended “a deflection option... based on a nuclear explosive device, which it found to have the highest probability of success” — to decision-makers it does not control, with legal and political implications it has no standing to resolve. Planetary defence shows that where the object of governance is a rock with an orbit, weak institutions suffice. It does not show that strong ones exist.
“We do not know how likely the great natural catastrophes are.” Established For two of them we know better than for anything humans might do deliberately. VEI 7 eruptions recur approximately one to two times per thousand years globally, with corrected estimates closer to two; the last was Tambora in 1815 at 41 ± 4 km³ dense-rock equivalent, and the 1257 Samalas event at 33–40 km³ carried an ice-core sulfate signal about 2.5 times Tambora's, probably triggering the Little Ice Age, with growing seasons 15–20% shorter. The volcanologists' own governance sentence is the one to quote: “No volcano observatory or community will stay on high alert for events like VEI 7 eruptions that occur globally only once or twice per millennium.” Handwave And a caution about the advocacy literature on the same subject: a 2026 conference report by a catastrophic-risk consultancy cites a keynote figure of a 70% chance of Pinatubo-scale cooling before 2100. Pinatubo was VEI 6. That figure is circulating as a VEI 7 probability and it is not one.
“There is a nuclear accident rate.” Handwave There is not, and it should be stated as a correction because so much writing implies otherwise. There is a numerator — documented incidents — and expert elicitation that a government-commissioned assessment characterises as spanning “negligible to greater than 80%” for a twenty-first-century nuclear war, which is a way of saying there is no estimate. Frontier Near-miss catalogues should likewise be cited with their authors' own caveats: classification limits, post-publication corrections, and an internal disagreement about how many cases the canonical study contains.
“Arms control demonstrably prevented proliferation.” Frontier Nobody can show this and the serious literature says so. Kennedy expected “15 or 20 or 25 nations” with weapons by the 1970s and there are nine. No party has built a weapon while under safeguards. Both facts are equally consistent with a treaty that constrains and with a treaty that screens states which were never going to proliferate — Betts, Solingen and Hymans against Nye, Walsh, Coe and Vaynman, and Fuhrmann and Lupu. The sentence both camps must accept: “we are unlikely to definitively identify the true causal effect of the NPT on nuclear proliferation empirically because history does not provide us with a counterfactual world in which there was no NPT.”