Skip to content

Main Insight

The third part of our Global Red Lines for AI series explores why and how red lines should be established at the global level. It outlines potential pathways and key considerations for driving meaningful progress in the years ahead.

Part 3: How Can Global Red Lines for AI Be Established?

July 3, 2025

This article is the third part of a three-part explainer series on Global Red Lines for AI. You can find the series overview here, part 1 here, and part 2 here.

Creating global AI red lines is no longer a theoretical exercise. The risks are real and political momentum is growing. But turning this into an enforceable, global framework will take action. 

In Part 1 and Part 2 of the red lines series, we established what red lines for AI governance are and how they are being used in practice. In this third piece of our red lines series, we outline what it will take to move from aspiration to action, and propose three concrete next steps to advance the effort.

Is establishing global red lines for AI easy?

Short answer: No, but we need them anyway.

Long answer: Despite growing momentum for AI red lines and a strong foundation in regulatory, multilateral, and civil contexts, turning this concept into a robust global reality will not be simple. Defining and enforcing meaningful boundaries runs into three major obstacles: geopolitical fragmentation, technical uncertainty, and institutional gaps. To overcome these challenges, we first need to understand them. 

First, geopolitical fragmentation. The world’s leading AI powers, including the United States, China, and the European Union, have different approaches to AI governance. These divergences reflect both distinct values and strategic priorities. For instance, the EU AI Act explicitly bans social scoring systems. In contrast, although China has endorsed UNESCO’s AI Ethics Recommendation, various local governments continue to deploy social scoring in practice.

Strategic competition makes coordination even harder. Some governments view strong regulation as a constraint on innovation or national competitiveness, fueling a regulatory “race to the bottom.” But this is a false tradeoff. Smart, well-designed regulation can support innovation while enhancing safety and protecting our fundamental rights. 

Global red lines for AI serve a targeted purpose: establishing clear boundaries around only the most dangerous behaviors and uses of AI technology. By focusing exclusively on preventing the most serious risks and unacceptable harms, red lines avoid creating unnecessary barriers to beneficial AI development and deployment. This approach preserves space for innovation while ensuring that AI progress remains aligned with human values and societal wellbeing.

Second, technical uncertainty and the difficulty for compliance. Some of the most concerning AI behaviors, such as deception, autonomous replication, and power-seeking strategies, manifest in unpredictable ways. We still lack mature tools to assess, monitor, or even clearly define these risks as they emerge and escalate. To close this gap, we need interoperable evaluation methods, early warning systems, and frameworks to analyze cascading failures.

But, importantly, the burden of proof must lie with AI developers. If they cannot empirically demonstrate that their system will not cross established red lines by making a reasonable, evidence-based safety case, they should not be allowed to develop or deploy it.

Third, institutional gaps. We currently lack global infrastructure to oversee and enforce red lines for AI. Most multilateral statements and corporate commitments are non-binding and lack accountability. What’s needed is a credible, independent oversight regime with the mandate, access, and capacity to monitor compliance, set incentives, and enforce consequences. Building that will require thoughtful institutional design and international cooperation, as well as research into monitoring and enforcement mechanisms to address challenges specific to red lines for AI.

What are the pathways toward a global AI red lines regime?

Despite the challenges, building an effective regime of global AI red lines is both necessary and possible. History shows that even in highly fragmented international environments, progress can be made. In fields like arms control and biosecurity, for example, states have established regimes through a combination of tools: binding treaties, voluntary norms, bilateral agreements, and soft law mechanisms. The literature on global governance underscores that no single instrument is sufficient. Instead, durable regimes are often the result of overlapping and reinforcing efforts, where soft law and hard law interact to create a robust architecture for coordination and accountability. The choice between them is not binary; rather, they function as complementary pillars of effective global governance.

With this in mind, we identify four main pathways toward building a functional and legitimate regime for global AI red lines. Each has distinct advantages and limitations, but they are not mutually exclusive. Progress in one area can help reinforce momentum across the others.

Figure 1. Four Pathways Toward a Global AI Red Lines Regime

Four Pathways toward a Global AI Red Lines Regime
PathwayDescriptionExample scenarioAdvantagesChallenges
Legally binding treatiesFormal agreements that can be enforced under international lawUN member states sign a treaty banning autonomous nuclear-launch systems • Clear legal obligations
• Potential for institutionalized monitoring
• Slow to negotiate
Difficult to enforce
• Key countries may not join or ratify
• Sometimes diluted to achieve consensus
International norms and declarationsNon-binding standards issued by global bodies NATO members affirm a red line on autonomous AI weapons, shaping expectations despite no legal force• Broad participation
• Enables agenda-setting and norm diffusion
• No enforcement mechanism
• Often diluted to achieve consensus
• May be ignored
Bilateral or multilateral agreementsTargeted pacts among countries or blocsG20 countries agree on red lines prohibiting AI labs from developing AI models that can self-replicate or self-improve• Easier and faster to negotiate than universal treaties
• Tailored to key risks
• May foster trust-building
• Close diplomatic and trade relationships can support effective implementation
• Frequently excludes smaller states
Prone to collapse under geopolitical strain
• Limited accountability mechanisms
Non-treaty commitmentsVoluntary codes, pledges, or principles from states and/or companiesCoalition of states, labs, and civil society organizations sign a non-treaty prohibiting the red lines proposed by IDAIS Flexible and adaptive
• Quicker to launch 
• Can include non-state actors like companies
• No legal consequences
• Risk of symbolic or inconsistent implementation
• Potentially likely to be biased towards commercial interests

Table 1: Four pathways toward a global AI red lines regime

What are concrete next steps?

A multi-pathway approach is the only viable way forward. States, companies, and civil society all have roles to play. Coordination will be difficult, but fragmentation doesn’t have to mean failure. If anything, the diversity of these pathways gives us a broader foundation from which to build.

We close with three concrete steps that can help tangibly advance the creation of meaningful global AI red lines:

  1. Build an inclusive coalition of the willing. 

We should not wait for universal agreement to begin. A “coalition of the willing” including governments, international institutions, responsible companies, civil society, and academia can take the first steps. The IDAIS Statement offers a foundation for consensus. Now it must be expanded through broader support from scientists, policymakers, and civil society leaders to build momentum for global action.

Crucially, red lines will lack legitimacy if shaped only by dominant actors. Global South governments, Indigenous communities, and underrepresented voices must be at the table. Inclusion is essential to designing red lines that reflect global values and lived realities.

  1. Chart a diplomatic path toward an international treaty on AI red lines. 

With growing momentum, the next step is to operationalize red lines within today’s political realities. Engaging the diplomatic community is key. Rather than waiting for universal consensus on all red lines, we should work closely with diplomats to chart clear, incremental pathways toward a binding international framework. Bilateral and regional agreements, non-binding multilateral norms, and standards can serve as stepping stones. 

These efforts need not cover every potential red line. Instead, they can focus on areas where policy windows are already open. Several red lines already enjoy broad support: for example, banning self-replicating AI systems, ensuring human oversight of nuclear command-and-control, prohibiting mass surveillance, impersonation of humans, manipulation of children, and large-scale influence operations using synthetic media. This kind of scaffolding can help build trust, define norms, and establish the legal and institutional infrastructure needed for future treaty commitments. 

  1. Develop blueprints for monitoring and verification mechanisms. 

For these red lines to be effective in reality, they need to be introduced with infrastructure for monitoring and verification. We must be prepared to operationalize them technically, legally, and institutionally. This means developing mechanisms for monitoring and verification: tools to verify compliance in advance of deployment, detect violations after deployment, and attribute responsibility when rules are broken. Ultimately, responsibility should lie on the developers to prove their systems adhere to red lines and to face serious consequences if not. One example could be hardware-enabled assurance mechanisms, which can monitor the uses of AI chips and block non-compliant computations. Other technical components might include independent audits, system reporting protocols, and forensic capabilities. This will likely also require funding for research and development of verification mechanisms and running pilots. 

But technical tools alone aren’t enough. Institutional design is equally critical. Who monitors? Who investigates? What happens if red lines are crossed? How is trust maintained among states with conflicting interests? We need oversight bodies with independence, legitimacy, and the resources to act. Monitoring and verification must evolve alongside red lines, not lag behind them.

Figure 2: Three Steps Towards Global Red Lines for AI

Conclusion

The way forward is clear: it is time to transform the growing momentum around AI red lines into concrete, enforceable global action. Through this three-part explainer series, we have established that red lines serve as critical safeguards against the most dangerous AI behaviors and uses, and demonstrated that foundational policies are already emerging across different jurisdictions and contexts. The real challenge lies in scaling these efforts to match the global nature of AI risks. 

The window for proactive governance is narrowing as AI capabilities advance rapidly, making it imperative that we move beyond fragmented, voluntary approaches toward coordinated international frameworks with genuine teeth. 

The question is no longer whether we need AI red lines, but how quickly we can build the international cooperation necessary to make them a reality.

Related resources

How To Make International AI Verification a Reality

How To Make International AI Verification a Reality

Countries outside the U.S.–China AI race can build the verification technologies needed to make an international agreement to slow AI development enforceable. This memo suggests research priorities.

What compute on European soil might buy Europe and what it depends on

What compute on European soil might buy Europe and what it depends on

Across Europe, there is growing appetite for locating large compute capacity at home. This post maps what the benefits' proponents claim such a buildout might bring and the key open questions these claims stand or fall on.

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

AI rules cannot reliably protect people when compliance cannot be checked. In a new CIGI policy brief co-authored by George Gor (TFS) and Kofi Yeboah (Mozilla), AI-enabled weapons in Africa serve as a case study of how procurement and regional verification can test supplier claims, reduce risks to civilians and...

The Case for Cross-Border AI Incident Infrastructure

The Case for Cross-Border AI Incident Infrastructure

AI incidents are scaling fast, and coordinated global governance is lagging behind. This report proposes addressing this challenge through the development of internationally-distributed incident management infrastructure. Our recommendations aim to enable governments, multilateral bodies, and frontier AI companies to jointly detect, prepare for, and respond to AI incidents across jurisdictions.

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

The EU's AI Act and Code of Practice requires providers of the most advanced AI models to meet the ‘state of the art’ (SOTA) in safety and security. In a new policy memo, we argue that SOTA is best understood as a process-driven concept, advanced by the broader expert ecosystem.

EU AI Act meets AI Agents

EU AI Act meets AI Agents

Highlights from Tech Policy Press article “The EU AI Act is Not Ready for Agents,” examining how the EU AI Act applies to AI agents and governance challenges.