§ Doctrinal position · Artificial intelligence & International governance

What can be verified?

Cassandra is believed, now: what is missing is no longer the warning, it is the architecture that would make restraint rational.

I

The inversion of Cassandra

The curse is well known: to speak the truth and not be believed. The governance of artificial intelligence is living its inversion. In May 2023, a single-sentence statement, signed by the leaders of the principal laboratories, placed the risk of extinction from AI among global priorities, alongside pandemics and nuclear war. Some of those same leaders asked the United States Congress for a regime of licences and mandatory evaluations. These warnings were not ignored: they were heard, commented upon, institutionalised into summits, joint declarations, evaluation institutes. And the race continued. Each generation of models has succeeded the previous one at a pace nothing has bent.

The available narratives do not capture this configuration. Prometheus and Frankenstein presuppose a creator whom the consequence of his act instructs too late: knowledge arrives there after the deed. Here, lucidity precedes the act, precedes it publicly, and does not suspend it. The problem is therefore no longer knowledge of the risk. It lies in the structure of the race.

II

The structure of the race

That structure can be described simply. No laboratory can slow down without factoring in the hypothesis that its competitor will press on. No State reasons on its intentions alone: if Washington chooses restraint, it must factor in what Beijing would make of it; Beijing reasons on the lead it would concede to Washington. At every level, cooperation can be collectively preferable without being individually rational, as long as each is ignorant of whether the other will cooperate.

It will be objected that the actors play a double game. The executives who called for guardrails before Congress are those whose organisations and backers have since fought some of the constraints liable to be imposed on them. But the most instructive piece of evidence lies elsewhere. It lies in the use the federal public power makes of its own authority. The presidential executive order of 11 December 2025 tasks a Department of Justice task force with challenging State legislations judged incompatible with federal policy and orders the preparation of a legislative pre-emption framework; and it explicitly justifies that policy by the objective of maintaining and strengthening the global dominance of the United States in artificial intelligence. The federal power does not use its authority to constrain the laboratories: it uses it to constrain the federated States that would constrain them, and it gives the reason itself. The logic of the race does not have to be inferred: it appears in the text. The most effective federal constraint bears on export, a constraint directed at the rival, which accelerates the race instead of slowing it.

This picture does not establish duplicity. It establishes the equilibrium. Each can wish for a common rule without accepting to be slowed alone; a State that reasons on its rival protects its laboratories instead of constraining them. To treat this configuration as a failure of responsibility, and to answer it with exhortation, is to mistake its nature: an equilibrium is not displaced by injunction. The conditions in which each actor takes its decision must be modified.

III

The precedent: restraint has never rested on virtue

Institutional history offers here a precedent more useful than the myths. The arms control regimes that produced effects did not rest on confidence in the adversary's virtue. The 1987 Intermediate-Range Nuclear Forces Treaty eliminated an entire category of weapons because it organised, for the first time, on-site inspections at the adversary's facilities. The New START treaty held by resting on an apparatus of inspections, data exchanges and reciprocal notifications. The safeguards of the International Atomic Energy Agency give the Non-Proliferation Treaty its eyes.

Conversely, the 1972 Biological Weapons Convention states a complete prohibition of development, production and stockpiling, without a verification mechanism. The protocol meant to give it one, negotiated for six years, was abandoned in 2001. More than fifty years after the convention opened for signature, the States parties are still working on the measures that would make it possible to establish compliance or violation credibly. The prohibition is acquired; the apparatus remains under construction.

The lesson is constant: what distinguishes effective regimes from declaratory regimes is not the ambition of the prohibition, it is the existence of an apparatus reducing uncertainty: verification, detection of violations, cost of defection, reciprocity. Restraint becomes rational the day the other's defection is detectable, and costly.

IV

What, in artificial intelligence, can be verified

It will be objected that the analogy stops where the object begins. A warhead can be counted, a silo observed by satellite, a nuclear test detected on the other side of the world. A model is a file of weights: copiable, transferable, concealable. The final object does not let itself be inspected like a site. The objection is exact, and that is precisely why it moves the question to the right place: if the product of the race escapes observation, its inputs do not.

For the race has an observable input: compute. Frontier training runs mobilise tens of thousands of accelerators for months, in identifiable centres, fed with measurable energy, supplied by one of the most concentrated industrial chains in the world. The law has, moreover, already taken hold of it, on both sides of the Atlantic. Article 51 of the European regulation on artificial intelligence makes the cumulative amount of compute used for training one of the criteria of presumption of systemic risk: where capabilities remain difficult to grasp directly, the law mobilises a quantifiable input. American export controls first bore on chips, because chips can be counted. To these are added, scattered, the first organs of a verification function: public evaluation institutes constituted in a network, commitments to pre-deployment testing, nascent obligations to report serious incidents. These fragments exist. They are dispersed, for the most part voluntary, without organised reciprocity: instruments of verification without a regime of verification.

The institutional question then becomes determinable. Not what should be prohibited or slowed, a question on which no actor will concede what it believes to be an advantage, but what can be verified, by whom, with what rights of access, and at what cost for the one who cheats. It is a question of architecture before being a question of norm.

V

Closing

The governance of artificial intelligence has treated the question successively as a problem of conscience, through the warnings, then as a problem of norm, through the announced prohibitions. It now encounters what arms control had learned before it: a prohibition without an apparatus of verification is a declaration, and a declaration does not displace an equilibrium.

The question is not whether the actors are sincere. It is what an architecture would allow them to believe of one another.

Cassandra is believed, now. What is missing is no longer the warning. It is the architecture that would make it possible to act on it.

Paris, September 2026

Sources · Executive Order 14365 of 11 December 2025, 90 FR 58499 · Center for AI Safety, "Statement on AI Risk", 30 May 2023 · U.S. Senate, "Oversight of A.I.: Rules for Artificial Intelligence", 16 May 2023, S. Hrg. 118-037 · INF Treaty, 1987 · New START Treaty · IAEA safeguards under the NPT · Biological Weapons Convention, 1972, and abandonment of the verification protocol, 2001 (UNODA) · Regulation (EU) 2024/1689, Article 51(2).

Related positions · Who determines the conditions? · What can the State requisition?

Maître Hannan Otmani, Avocate au Barreau de Paris
Architect of the AUCTORITAS · WISER · DELEX ecosystem
§ DELEX CONSORTIUM — Where doctrine becomes public voice

Doctrinal position published by DELEX Consortium, doctrinal chamber of the ecosystem. The qualification work from which it proceeds is conducted within AUCTORITAS, institution of strategic qualification. The reading is accessible. The protocol that produces it remains reserved.

All positions