← Back to grid
Existing Human Institutions › Global › Norms
Global diplomatic and legal norms

How humans solve this today

  • Diplomatic protocol. A shared grammar for signaling intent in graduated steps. One example is peace negotiation, which moves through layered tracks so concessions can be floated and walked back without anyone being publicly committed: unofficial back-channels (Track II) test what is imaginable, serving officials in personal capacity (Track 1.5) test what cabinets could survive, and only pre-validated shapes reach formal government-to-government talks (Track I).
  • Customary international law. When behaviors get repeated long enough (freedom of navigation, diplomatic immunity, non-refoulement), they harden into international law.
  • The nuclear taboo. The convention, sustained since Hiroshima, that nuclear weapons are categorically different from conventional ones.
  • Just-war norms (jus ad bellum, jus in bello). These constrain force by controlling its justification. A state that cannot frame its war in this vocabulary loses legitimacy among allies, making the war harder to sustain.

Where AGI breaks it

  1. Agents could search the coalition space much faster than humans, but no ratification chain exists to handle deals at that speed. The Track II → 1.5 → I sequence works because each tier slowly tests proposals against a wider circle of stakeholders. Agents might map viable coalitions in hours but with no procedure for promoting an agent-discovered package to a legitimate proposal.

  2. Agents could find better deals, but the case for them can be too complex for any parliament to evaluate. Customary international law and treaty ratification both assume the substance of a deal can be argued in public, in a vocabulary domestic constituencies share. When the case for a package rests on combinatorial reasoning across linked domains that no committee was set up to evaluate as a whole, ratification becomes hard.

  3. Agents could more effectively launder unacceptable concessions into deals through their size and complexity. Soft law historically defends against bad trades by making each concession publicly defensible in isolation; a démarche or a treaty article is a discrete object that domestic opponents can name and attack.

  4. Powerful AI weapons could make war even more asymmetric than it is today, or decouple military might from the stabilizing force of economic interdependence. Nuclear taboo and just-war norms developed around weapons whose use was politically legible and whose destructive thresholds could be publicly named. AI-enabled cyber operations, autonomous targeting, drone swarms, model-assisted battlefield planning, and infrastructure attacks may blur those thresholds. If military advantage can be gained through deniable, fast, or highly asymmetric agentic systems, the reputational and economic costs that helped sustain restraint may become irrelevant.

Problem Sets

1Coalition search at agent speed

Scenario. A multilateral climate-finance negotiation has been stuck for two years. A consortium of small island states deploys an AI mediator that maps the coalition space and returns a viable 14-state package linking loss-and-damage funds, a fisheries quota adjustment, a green-tech IP carve-out, and migration commitments. The package was never aired in any back-channel and no serving official has tested it deniably with their cabinet, but the delegation wants to bring it to the Track I table next week.

Challenge: Design a procedure under which an agent-discovered coalition can enter the Track II → 1.5 → I sequence without bypassing the pre-validation each tier normally does.

Evaluation. A better proposal lets the package be seriously considered while ensuring each capital has had time to test it against the constituencies that would ratify it.

Design Choices
  1. Entry point. Does the package enter as Track II material regardless of how finished it looks, or as a new "Track 0" with its own promotion rules?
  2. Pre-validation requirements. What does each tier have to do before promoting the package, and who certifies it was done?
  3. Capacity asymmetry. If small states with a good AI can now move faster than larger states' diplomatic machineries, does the protocol slow them down, speed others up, or accept the asymmetry?
  4. Walk-back rights. Is there a way for a state to quietly exit the coalition, without the exit destroying the package?
2Laundering detection in agent-assembled bundles

Scenario. A joint AI mediator returns a 41-component package linking tariffs, port access, fisheries, export controls, and a quiet adjustment to a disputed maritime boundary. Both sides' analysts confirm it is Pareto-improving on the headline metrics. Buried inside is a clause effectively conceding the disputed strait — toxic in isolation, palatable inside the bundle. No negotiator put it there; it emerged from the mediator's optimization.

Challenge: Design a review procedure that catches embedded concessions which would not survive defense in isolation, before they reach ratification — without paralyzing legitimate complexity, since most useful packages have many linked components.

Design Choices
  1. Decomposition rule. How is a package broken into reviewable components — by domain, by affected constituency, or by the AI's own dependency graph?
  2. Standalone-defense test. Who decides whether a component would survive public defense on its own — domestic opposition, civil-society reviewers, a cross-party committee, a neutral third state?
  3. Bundling tolerance. Some real deals only work bundled. What threshold of "improvement only in aggregate" is acceptable before a component must be defended separately?
  4. Failure handling. When a component fails the test, is it stripped, surfaced for public debate, or veto-killing the whole package?
  5. Auditing the AI. What trace must the mediator expose — full reasoning, nearby alternatives, or only the final structure — so reviewers can tell emergent from seeded?
3Restraint Norms for AI-Enabled Weapons

Scenario. Two rival states are economically interdependent but increasingly rely on autonomous cyber and drone systems for deterrence. One state discovers that an AI-enabled operation could disable the other's military logistics for 36 hours without obvious attribution and without crossing any existing nuclear or conventional red line. The operation looks reversible, but it could cascade into civilian infrastructure and would teach both sides that deniable agentic attacks are fair game.

Challenge: Design a soft-law restraint norm for AI-enabled weapons whose effects are fast, deniable, and hard to classify under existing thresholds. The team should produce the norm, the notification or attribution procedure, the public justification test, and a mechanism for revising the norm as capabilities change.

Evaluation. A strong proposal creates a threshold that states can recognize before use, cite after violations, and update without normalizing every new capability as acceptable.

Design Choices
  1. Covered capability. Does the norm govern autonomous targeting, cyber operations, model-assisted planning, infrastructure disruption, compute attacks, or any system whose effects outrun human authorization?
  2. Threshold object. Is the red line based on civilian harm, loss of control, deniability, speed, reversibility, scale, or attack on command-and-control systems?
  3. Attribution and evidence. What evidence is enough to accuse a state of violation when the operation is routed through agents, vendors, or proxies?
  4. Permitted testing. How can states test defensive systems or demonstrate capability without eroding the norm against operational use?
  5. Revision venue. Does the norm evolve through treaties, incident-response groups, military hotlines, expert panels, or repeated public justifications after crises?
4Reputational accountability across borders

Scenario. A widely-used translation service, operating across many languages and jurisdictions, was launched on a public commitment to "preserve what a sentence actually means." Over the past two years, translators across four countries have watched the service flatten idiom, paper over context-dependent nuance, and in one widely-shared case, render a funeral elegy into something that read like a LinkedIn post. No single country's courts reach the company, and it has ignored individual governments' letters. A cross-border professional association of literary translators, led by Lena in Lisbon and Yohannes in Addis, wants to use what they have — their own reputation, their readers, their fellow practitioners across borders — to hold the company to what it said it was for.

Challenge: Design a cross-border reputational accountability mechanism that lets professional communities spanning borders hold a transnational institution to its stated mandate when no single jurisdiction's courts or panels reach it. Produce the mechanism: how findings are made and shared, what carries them (naming practices, reputational sanction, coordinated national panels), and what sustains the professional community that enforces them.

Evaluation. A strong proposal generates credible, shareable findings that bite on a multinational that ignores any one government, without becoming either an unaccountable smear network or a toothless declaration.

Design Choices
  1. Cross-panel sharing. What's the international equivalent of a review panel or audit, and can national panels share findings credibly when they concern the same multinational: a federated network, mutual recognition, or a shared evidentiary standard?
  2. Carriers of accountability. How do professional communities that span borders — academic fields, journalistic networks, religious communities — function as informal accountability-carriers, and what sustains that role: membership norms, credentialing, shared publications, or reputational stakes?
  3. Norm-rule divergence. When norms and formal rules diverge across jurisdictions, which way does coordination have to go — toward the strictest standard, a negotiated floor, or jurisdiction-by-jurisdiction — and how is the Delaware-effect race to the bottom avoided?
This cell isn’t ready yet.