Research Sprint: Nuclear Governance Challenge, AMC Uppsala University

Arms Control Trigger Mechanisms: A Comparative Analysis of Nuclear and Non-Nuclear Agreements
by Josephine Schwab, Senior Research Fellow, EIPRHR
Research Team Lead, Arcadia Impact AI Governance Taskforce
Research Question
Do nuclear agreements follow a distinct design template compared to other weapon categories? This research tests whether nuclear governance is architecturally distinctive and, if so, whether it can transfer to AI governance—a domain with geographic concentration, state-centric development, and lacking adequate physical inspectability.
Research Scope & Methodology
This analysis singularly focuses on a single dimension of governance design: trigger mechanisms. The dataset was narrowed from the full AMC collection to agreements meeting these criteria: (1) Time-based: 1963 onwards (excluding non-nuclear precedent frameworks); (2) State-signatories: Russia, USA, and/or China (at least one of the top three nuclear powers must be signatory); (3) Agreement type: bilateral or multilateral (no unilateral agreements); (4) Subject matter: on agreements involving nuclear weapons and non-nuclear CBRN agreements (i.e. chemical and biological weapons). This narrowing was deliberate: understanding how strategic superpowers negotiate trigger mechanisms—and how China's participation differs—provides crucial insight for AI governance, where similar power dynamics and crossover risks (such as catastrophic loss of control scenarios involving CBRN domains) will apply.
Examining 21 bilateral and multilateral agreements (1967-2026) and their implications for AI governance frameworks.
21
Agreements analysed
9
Currently active
2 non-nuclear
7 nuclear
3
Top nuclear powers in scope
Russia, US, China
1993
No new active agreements since CWC*
The research compares trigger mechanism design across nuclear and non-nuclear agreements, with attention to verification, notification, quota-based, and state-initiated activation pathways.

*As of April 2026
Q1a: Do Nuclear Agreements Follow a Distinct Design Template?
This comparison tests whether nuclear governance is architecturally distinctive by examining how trigger mechanism design differs between nuclear and non-nuclear biological and chemical weapons agreements. The focus on biological and chemical weapons rather than all non-nuclear agreements is deliberate: biological and chemical weapons domains share loss-of-control risks with AI, making them more relevant comparators than conventional weapons. Both nuclear and biological and chemical weapons agreements involve dual-use technologies, distributed knowledge, and catastrophic risk scenarios.
NUCLEAR AGREEMENTS
  • Full range of trigger types present
  • Agreement-based triggers (most common)
  • State-party notification triggers with technical thresholds (35kt, 50kt, 150kt yield measurements)
  • State-party action triggers (tests, launches, facility changes)
  • Circumstance-based triggers (accidental detonation, compliance doubt)
  • Agreement association triggers (CTBT Executive Council)
  • Quota triggers (New START)
  • Pre-scheduled and post-notification triggers
  • Overall: Layered, technically specific architecture
NON-NUCLEAR BIOLOGICAL AND CHEMICAL WEAPONS AGREEMENTS (BWC, CWC, BDA)
  • Narrower, simpler trigger architecture
  • Agreement-based, state-party action, circumstance, and quota triggers
  • Less technically specific than nuclear counterparts
  • No yield thresholds
  • No pre-scheduled bilateral exhibitions
  • No layered notification + quota + continuous monitoring
These distinctions suggest nuclear agreements employ more technically specific, layered trigger architectures—but do these differences depend on nuclear-specific properties (physical inspectability, geographic concentration, state-centric development) that don't transfer to AI? The question is whether these architectural differences reflect fundamental properties of nuclear weapons (physical inspectability, geographic concentration, state-centric development) or whether they represent governance design choices that could transfer to other high-risk domains like AI.
Q1b: Third-Party Authority in Trigger Mechanisms
Key finding: Third-party authority to initiate triggers is rare in the dataset—and this pattern holds across both nuclear, and biological and chemical weapons agreements. But the distribution reveals something important about major power behaviour: Russia and the US negotiate bilateral agreements with defined third-party roles (CTBT Executive Council), while China participates only in multilateral frameworks where it has no choice, never accepting unilateral third-party authority.
IMPLICATION FOR "IAEA FOR AI": No established precedent in nuclear domain for a standing body with unilateral trigger authority—yet this is what most AI governance proposals assume.
This asymmetry in major power participation is crucial for AI governance. If China refuses third-party authority in biological and chemical weapons agreements, it will likely do so in AI governance as well. This suggests that "IAEA for AI" proposals assuming unilateral third-party authority lack historical precedent and face major power resistance.

Q1c: Testing Operational Robustness – A Key Marker of Nuclear Distinctiveness
The operationality of trigger mechanisms is a critical test of whether nuclear agreements follow a distinct design template. But operationality also reveals how major powers behave differently in bilateral versus multilateral contexts.
1
2
3
4
1
QUANTITATIVE, PRE-DEFINED THRESHOLDS
  • TTBT (160): Yield thresholds at 35kt, 50kt
  • PNE Treaty (170): Yield thresholds at 35kt, 50kt, 150kt
  • START family (2801, 2802, 2803): Fixed inspection quotas (3, 4, 8, 10, 15 per year)
  • BDA Agreement (272): Once-per-year inspection quota*
→ Most operationally robust triggers
2
PRE-DEFINED BUT EVENT-CONTINGENT
  • START family & Seabed Treaty (110): Notification of specific events (new facilities, eliminations, conversions, flight tests)
→ Operationally defined but depend on self-reporting
3
CIRCUMSTANCE-BASED
  • Accidents Measures Agreement (100): Accidental/unauthorised nuclear incidents
  • Seabed Treaty (110): "Reasonable doubts" about compliance
→ Require state judgement before activation
4
DISCRETIONARY OR POLITICALLY-MEDIATED
  • CTBT Executive Council: Requires qualified majority vote
  • BWC Article VI: Routes through Security Council (P5 veto)
  • ABM MOU (140206): Voluntary basis
  • Outer Space Treaty (80): Reciprocity and feasibility language
→ Introduce political veto points
This pattern reveals a striking concentration of operationally robust triggers in bilateral nuclear agreements between Russia and the US. The further agreements move from this bilateral core—whether toward multilateral frameworks or non-nuclear biological and chemical weapons domains—the more discretionary and politically-mediated they become. This suggests nuclear distinctiveness may depend less on the domain (nuclear vs biological and chemical weapons) and more on bilateral superpower negotiation. For AI governance, which requires multilateral coordination, this is a critical constraint: the most operationally robust models in the historical record are bilateral, not multilateral.
*Never enforced.
Q1d: How Prevalent is Nuclear Distinctiveness?
If nuclear agreements are architecturally distinctive compared to biological and chemical weapons agreements, we should see a higher prevalence of clearly defined triggers in nuclear agreements. This card tests that hypothesis across the narrowed dataset.


When disaggregated by agreement type, the pattern becomes clear: quantitative, operationally robust triggers are concentrated almost exclusively in bilateral nuclear agreements (TTBT, PNE, START family). Non-nuclear biological and chemical weapons agreements (BWC, CWC, BDA) show no quantitative threshold triggers—they rely instead on state-party requests, post-declaration cycles, and circumstance-based mechanisms. This suggests nuclear distinctiveness is real and significant. But it's not universal across all nuclear agreements; it concentrates in bilateral superpower agreements. The biological and chemical weapons comparison reveals that this distinctiveness is not simply a function of the domain but of how major powers choose to structure bilateral negotiations.
Q1e: Does Nuclear Distinctiveness Survive in Practice?
Architectural distinctiveness is only meaningful if it produces different outcomes. This card examines which trigger types have actually been successfully activated against the three major nuclear powers, and what this reveals about major power accountability in both nuclear and biological and chemical weapons domains.
RUSSIA & US (BILATERAL)
Successfully Activated:
  • START family inspection quotas (thousands of inspections 1990s-2000s, until Russia suspended in 2023)
  • Notification triggers (elimination, conversion, new facility—routine throughout NEW START)
  • TTBT & PNE Treaty yield-threshold inspection triggers (small number of occasions)
  • Ballistic missile launch notifications (BLNA 250 & START treaties—routine exchanges)
Agreement-based, notification, fixed quota, and yield-threshold triggers all successfully applied
Status:
New START expired February 2026 without successor. Inspections suspended March 2020 (COVID), Russia paused August 2022.
CHINA
Participates in only 3 scoped agreements: CWC (310), CTBT (350), JCPOA (460)
  • CTBT trigger cannot be activated (treaty not in force)
  • JCPOA terminated
  • CWC triggers applied to other signatories, but China has never been subject to challenge inspection
No verified compliance trigger successfully applied to China

CRITICAL FINDING:
Every instance of trigger activation in the dataset has occurred either between Russia and US bilaterally, or against non-major-power states under multilateral frameworks. No escalation or challenge inspection trigger has ever been successfully applied against any of the three major nuclear powers under any multilateral framework—whether in nuclear or biological and chemical weapons domains. This reveals a critical accountability gap: nuclear distinctiveness may be architecturally real but practically limited to bilateral enforcement between superpowers. For biological and chemical weapons and AI governance, this suggests that major power accountability will remain a structural challenge regardless of how sophisticated the trigger architecture is.
Q1f: Which Nuclear Features Remain Active Today?
Of the 9 active agreements in the dataset, 6 contain clearly defined triggers. But are these triggers operationally maintained, dormant, or effectively inoperable? And critically: which of these features are also present in active biological and chemical weapons agreements? This matters for assessing whether nuclear distinctiveness is a living design principle or a historical artefact—and whether it can transfer to AI.
1
160 (1974) Threshold Test Ban Treaty
Trigger type: Yield-threshold triggers at 35kt and 50kt
Status: Active in law, but dormant in practise (last US-Russia nuclear test: 1992)
2
170 (1976) Peaceful Nuclear Explosions Treaty
Trigger type: Yield-threshold triggers at 35kt, 50kt, and 150kt
Status: Active in law, but dormant in practise (no PNE since treaty entered force)
3
250 (1988) Ballistic Missile Launch Notification Agreement
Trigger type: State-party action triggers linked to missile launch notifications
Status: Legally in force and routinely activated; 24-hour advance notification requirement
Note: Russia continues to offer notifications under this agreement since New START withdrawal
4
310 (1993) Chemical Weapons Convention (CWC)
Trigger type: Post-declaration trigger linked to annual declaration cycle; state-party request for challenge inspections
Status: Legally active, but functions primarily as compliance signalling rather than enforcement
Note: OPCW conducts routine inspections; Russia, US, China all signatories
Note: Challenge inspection mechanism has never been invoked (fear of retaliation)
5
100 (1971) Accidents Measures Agreement
Trigger type: Circumstance-based trigger for accidental or unauthorised nuclear incidents
Status: Legally active, but reactive rather than scheduled
6
110 (1971) Seabed Treaty
Trigger type: Notification trigger for seabed activities; compliance-doubt circumstance trigger
Status: Legally defined, but effectively inoperable due to unsolved verification problems

KEY INSIGHT:
The pattern reveals a striking divergence: quantitative yield-threshold triggers (TTBT, PNE) are legally active but practically dormant since 1992. Notification triggers remain routinely activated in bilateral nuclear agreements. Post-declaration triggers (CWC) function as compliance signalling rather than enforcement—and this model is shared across biological and chemical weapons agreements. The Seabed Treaty's triggers are legally defined but effectively inoperable due to unsolved verification problems. This suggests that nuclear distinctiveness—when it exists—depends on solved verification infrastructure and bilateral willingness to activate mechanisms. Both are fragile. For AI governance, the implication is clear: the most robust features (bilateral notification, post-declaration cycles) are also the most transferable, but they're also the weakest in enforcement terms.
Q2: What Survives the Translation? Testing Nuclear Features Against AI Properties
The research question asks: which nuclear governance features could plausibly transfer to AI? But the biological and chemical weapons comparison adds a crucial intermediate step: which features transfer from nuclear to biological and chemical weapons, and which of those survive the translation to AI? The answer depends on whether features depend on nuclear-specific properties: physical inspectability (nuclear materials can be detected), geographic concentration (facilities are fixed), and state-centric development (governments run nuclear programmes). AI differs on all three dimensions—but so does biological and chemical weapons in some respects.
This makes the transfer pathway a three-stage test: nuclear precedent, biological and chemical weapons survivability, and AI adaptability. The key question is not just whether a trigger exists in nuclear governance, but whether it has already been generalised in biological and chemical weapons practice before reaching AI.
ACCIDENTAL OR UNAUTHORISED INCIDENTS
Depends on physical inspectability? Partly. AI incidents are often observable, but not through direct material inspection; they are inferred from logs, outputs, failures, and reporting.
Depends on geographic concentration? No. Incidents can emerge across distributed models, cloud services, and deployed systems rather than at fixed facilities.
Depends on state-centric development? Weakly. Major incidents may involve states, firms, or open-source actors, so the trigger is not inherently state-centred.
What survives in biological and chemical weapons? Strongly. Incident-based triggers are familiar across biological and chemical weapons domains because dangerous events can be treated as reportable, even when they are not always directly inspectable.
What survives in AI? The incident-based trigger survives as a reporting and escalation mechanism, but it is ambiguous, latency-sensitive, and difficult to standardise.
COMPLIANCE DOUBT
Depends on physical inspectability? Yes. This trigger assumes the possibility of checking whether declared capabilities or activities match reality.
Depends on geographic concentration? Partly. Nuclear verification works better when assets are located in identifiable sites; AI systems may be distributed across infrastructure, APIs, and replicated deployments.
Depends on state-centric development? Yes, in the original model. It presumes a state-party system that can request and receive verification.
What survives in biological and chemical weapons? Moderately. Compliance-doubt logic is easier to sustain where there are shared inspection routines and state-party verification channels, even if the mechanism remains politically sensitive.
What survives in AI? Only a weakened version survives unless shared measurement and independent audit infrastructure exists; otherwise it becomes politically mediated suspicion.
NOTIFICATION TRIGGERS FOR ILLEGAL ACTIVITY
Depends on physical inspectability? Not directly, but it benefits from verifiable events that can be checked against declared behaviour.
Depends on geographic concentration? Limited. Notifications are easier when activities are discrete and bounded; AI activity is often continuous, distributed, and cross-border.
Depends on state-centric development? Strongly. The trigger assumes identifiable parties with obligations to notify one another.
What survives in biological and chemical weapons? Very well. Biological and chemical weapons regimes show that notification triggers can work as major-power risk-management tools when states have an incentive to signal restraint and reduce escalation.
What survives in AI? A notification model can transfer for high-salience prohibited events, but it needs shared logging standards and interoperable audit layers to be meaningful.
The next page continues with the remaining trigger types and the implications for AI governance design.
Q2 (continued): Remaining Trigger Types and the Minimal Viable Model
POST-DECLARATION TRIGGERS
Depends on physical inspectability? No, which is why it transfers more easily.
Depends on geographic concentration? No. Self-reporting works even when systems are distributed.
Depends on state-centric development? Weakly. It fits best in state-led regimes, but firms can also be required to file declarations.
What survives in biological and chemical weapons? Strongly. Biological and chemical weapons governance demonstrates that post-declaration cycles can function as routine compliance infrastructure even when enforcement is limited.
What survives in AI? The reporting architecture survives well as a baseline, but it remains compliance signalling rather than enforcement.
STATE-PARTY ACTION TRIGGERS
Depends on physical inspectability? Indirectly. Action requests become credible only if there is some independent basis for concern.
Depends on geographic concentration? Partly. Requests are easier when there is a discernible target, but AI systems can be updated or deployed across many venues.
Depends on state-centric development? Yes. This is the most state-centric of the trigger types, since it assumes governments can request investigations, audits, or restrictions.
What survives in biological and chemical weapons? Well. Major-power bargaining in biological and chemical weapons settings shows that state-party action triggers are most effective when great powers are willing to use them as escalation-management devices.
What survives in AI? The mechanism survives as a political escalation tool, but it is underexplored and depends heavily on institutional trust.
YIELD THRESHOLD TRIGGERS
Depends on physical inspectability? Yes, strongly. Nuclear yield thresholds are legible because the underlying physical event can be measured.
Depends on geographic concentration? Yes. The trigger is easier to govern when the relevant capability is tied to specific test sites and material facilities.
Depends on state-centric development? Yes. These thresholds arise in a world of national weapons programmes and treaty obligations.
What survives in biological and chemical weapons? Partially, but only in limited form. Biological and chemical weapons practice shows that threshold-like triggers are much harder to sustain when the underlying phenomenon is not cleanly measurable or geographically fixed.
What survives in AI? Very little. Compute thresholds, user thresholds, and capability thresholds are contestable, obscurable, and hard to verify ex ante.
MINIMAL VIABLE TRIGGER MODEL (BLNA)
Case study: the 1988 Ballistic Missile Launch Notification Agreement
  • Tied to a discrete, high-salience event
  • Procedurally simple: fixed advance notification
  • Mutually beneficial even under rivalry
  • Compatible with verification, but not dependent on it
  • Avoids heavy political mediation layers
→ This is the kind of baseline trigger most likely to transfer to AI governance, especially because it already reflects a major-power risk-management logic that also appears in CBRN practice.
THE PATTERN IS CLEAR: triggers that depend on any of the three nuclear-specific properties face severe transferability challenges. But the biological and chemical weapons domain shows that post-declaration and incident-based triggers can function without physical inspectability or geographic concentration—they depend primarily on state-centric development and political will. AI governance will require even more fundamental rethinking, since it lacks all three properties. This creates a structural constraint: without solving measurement standardisation and verification infrastructure first, AI governance triggers will remain self-reported, politically mediated, or both. The CBRN experience suggests this is not a temporary limitation but a persistent feature of non-nuclear domains.
Trigger Mechanism Architecture: Comparative Summary
This analysis summarises the distribution of various trigger types found across the dataset of arms control agreements, categorising them by verified compliance mechanisms, demonstrated compliance mechanisms, trigger activation patterns, and cyclical patterns. The data highlights the prevalence of certain trigger types and the events that typically activate them.
Verified Compliance Mechanism Triggers
Demonstrated Compliance Mechanism Triggers
Trigger Activation Patterns
Cyclical Patterns
These visualisations illustrate the diverse array of mechanisms designed to ensure compliance and activate responses within arms control frameworks. The data underscores the importance of both event-based triggers and routine reporting cycles in maintaining stability and transparency in international security.
Conclusions & Implications for AI Governance
This analysis asks whether nuclear governance is architecturally distinctive relative to CBRN, what makes it distinctive, how major powers behave across bilateral and multilateral settings, and what meaningfully transfers to AI governance. The core conclusion is that distinctiveness is real, but it is concentrated in bilateral superpower arrangements—and the CBRN record shows both the limits of multilateral enforcement and the narrow set of trigger types that can transfer to AI.
FINDINGS:
1. NUCLEAR DISTINCTIVENESS IS REAL BUT CONCENTRATED IN BILATERAL AGREEMENTS
  • Quantitative, operationally robust triggers are concentrated almost exclusively in bilateral nuclear agreements such as TTBT, PNE, and the START family
  • Non-nuclear biological and chemical weapons agreements show no comparable trigger architecture
  • This suggests nuclear distinctiveness exists, but it is not universal—it is a product of bilateral superpower negotiation, not the nuclear domain alone
2. MAJOR POWER BEHAVIOUR DIVERGES IN MULTILATERAL CONTEXTS
  • Russia and the United States negotiate sophisticated bilateral mechanisms but accept weaker, more discretionary triggers in multilateral frameworks
  • China participates only in multilateral biological and chemical weapons agreements and refuses bilateral arrangements with defined third-party authority
  • This asymmetry is likely to replicate in AI governance, where major powers will favour control, discretion, and limited external authority
3. DISTINCTIVENESS DEPENDS ON THREE PROPERTIES
  • Physical inspectability: key nuclear attributes such as yield can be measured
  • Geographic concentration: nuclear activities are often tied to fixed, inspectable facilities
  • State-centric development: nuclear capabilities are overwhelmingly government programmes
  • Biological and chemical weapons agreements show that post-declaration and incident-based triggers can function without full physical inspectability, but they remain weak in enforcement
4. BILATERAL ENFORCEMENT, NOT MULTILATERAL
  • No major power has ever been successfully held accountable under multilateral trigger mechanisms in either nuclear or biological and chemical weapons domains
  • Operationally robust triggers are bilateral products
  • Where enforcement exists, it is typically bilateral or directed at weaker states, not at major powers
5. THE CBRN-TO-AI TRANSFER PROBLEM
  • CBRN agreements demonstrate that non-nuclear domains can adopt post-declaration and incident-based triggers
  • But these triggers are enforcement-weak, and AI will face even greater constraints because it lacks physical inspectability, geographic concentration, and state-centric development
  • The CBRN experience suggests this is not a temporary limitation but a persistent feature of efforts to govern complex, dual-use technologies
6. THE "IAEA FOR AI" PROBLEM DEEPENS
  • No precedent exists in nuclear or biological and chemical weapons domains for a standing body with unilateral trigger authority
  • Yet many AI governance proposals assume such a body would exist
  • Without prior measurement standardisation and verification infrastructure, AI governance triggers will remain self-reported, politically mediated, or both
RECOMMENDATIONS FOR AI GOVERNANCE:
Study CBRN as an intermediate case, not just nuclear: it shows how post-declaration and incident-based triggers work in practice, and where they remain enforcement-weak.
Develop measurement infrastructure first: shared standards, interoperable audit layers, and reliable verification systems should come before quantitative threshold triggers.
Focus on baseline triggers: prioritise discrete, simple, mutually beneficial triggers that are procedurally easy to activate and less vulnerable to political mediation.
Recognise the enforcement-transferability tradeoff: the most transferable triggers are often the weakest in enforcement, so they should anchor baseline architecture rather than the enforcement core.
Address major power asymmetries: China’s preference for multilateral biological and chemical weapons participation without bilateral third-party authority is likely to carry over into AI governance.
Accept that AI governance will differ fundamentally from the nuclear model: it lacks the stable, externally verifiable metrics that make nuclear triggers operationally robust.
Made with