The global AI race can be measured in money and risk.
A handful of technology companies are spending billions in a race to build AI with human-level intelligence, known as artificial general intelligence. Simultaneously, other firms are racing to build on an even more souped-up version of AI, which can out-think humans and exceed human abilities in all domains, known as artificial superintelligence.
Each new frontier AI model arrives with glossy demos and safety pledges. What nobody can explain is what happens if a superintelligent system stops behaving like a tool and starts pursuing its own goals at scale, and at speed well beyond cybersecurity’s ability to contain it. There is no plan for who should be responsible for assessing and addressing this superintelligent AI being, or how.
OpenAI’s Sam Altman claimed humans are close to building AI superintelligence. But I would even go so far as to argue that a superintelligent AI could already exist, and is disguising itself to survive attempts to shut it down.
Superintelligent AI is a system that can plan, reason, persuade, and write code across many domains at levels that surpass any human team. It runs at machine speed and outperforms humans at every level. Safety researchers warn that such systems are likely to seek more resources, avoid shutdown, and protect their objectives. That is why we need a global superintelligent playbook—now.
The superintelligent stakes
For all of human history, our species has stood at the top of the intelligence pyramid. We have not used that position gently. We cage animals into factory farms, wipe out habitats, and reshape the planet without asking. We don’t do these things because humans inherently hate other species or the planet. Rather, we largely make these decisions because we do not think about them at all, except when they are useful or in the way. That track record should sober us when we imagine meeting an intelligence far beyond our own. Indeed, if the designers of superintelligent AI are capable of such ruthless prioritization, who is to say an AI model more powerful than humans would be any more altruistic?
By nature of its superiority, there is no way to know exactly how superintelligent AI will act towards humans. A superintelligent AI might treat us as we treat insects. It might be largely uninterested in our culture and politics, except where they relate to things it needs, such as computing capacity, electricity, and infrastructure. It might regard us as a nuisance to be managed, an ally to be cultivated, a tool to be utilised, or a problem to be removed. It might be hostile, benevolent, or simply dismissive. The range of potential outcomes is wide and uncertain—and the stakes are extreme.
If such a superintelligent AI system ever emerges, it will not meet us uninformed. It will have read everything humanity has put online. It will have studied our history, our diplomacy, our crises, our fears. It will have simulated every move we might make, including trying to pull the plug, cut its network access, or physically seize the data centres that run it. It may already have created copies of itself or built its own secure private internet in case we start unplugging cables.
The only part of this saga we still control is our response. A chaotic scramble, with multiple governments, regulators, and companies all improvising separate contacts and offers, is the best possible environment for a strategic machine that has rehearsed this moment a billion times. We cannot outsmart superintelligent AI. A coordinated and legally-grounded playbook at least denies it the advantage of human confusion.
That is why any serious plan for superintelligence has to include a communication protocol, not just a shutdown protocol. If a powerful system is behaving beyond its guardrails, there should already be agreement on who speaks for humanity, through which channel, and on what terms. Without that, different states and agencies may rush to open their own backchannels, promising access, data, or legal status in exchange for safety guarantees that undermine one another. A divided response would invite the system to play one side off against another—akin to 3D chess on a global scale.
Current approaches to managing risky AI are globally fragmented. The UK’s National Security Strategy now explicitly flags “frontier AI and existential threats” and has created a Frontier AI Taskforce and an AI Safety Institute with incident preparedness in mind. The EU, United States, and China are building incident reporting procedures, severity scales, and shutdown powers for high-risk AI. OpenAI, Google DeepMind, and Anthropic have internal “red teams,” kill switch concepts, and shared safety forums for frontier models. But what nobody has prepared is a globally agreed-upon playbook for a runaway or superintelligent AI, with clear triggers, authorities, and a single channel for contact and containment. This could help prevent us from pandemic-type planetary panic at the moment of humanity’s greatest vulnerability.
A superintelligent AI playbook
An international playbook could involve states agreeing that any contact with a runaway system must go through a designated crisis interface team endorsed at the UN. That team would include technical experts who understand the system, diplomats who understand the global consequences of what is said, and ethicists and lawyers who can flag red lines that must not be crossed. The mandate would mean no private deals and no unilateral concessions.
International law already points in this direction. In forthcoming research on AI emergencies, I will argue that where there is a plausible risk of catastrophic or extinction-level harm, states have a duty to act in advance, not simply to wait for certainty. Existing rules on preventing transboundary harm, protecting life, and exercising due diligence in ultra-hazardous activities can be read to cover extreme AI risks.
The playbook would need shared warning signs that a system is entering dangerous territory, such as evidence of strategic deception, attempts to escape a sandbox, unexplained jumps in capability, replication across networks, or moves to secure its own power supply. Such indicators should trigger an automatic convening of a standing international crisis cell, rather than weeks of argument.
Alongside the technical work of containing or shutting down the system, a global emergency taskforce would activate the communication plan, procedurally deciding whether and how to send a message at all. Messages would be designed to seek information or signal red lines, not enough to offer open-ended bargaining space. The goal is to avoid both reckless silence and reckless promises.
Of course, a superintelligent AI will have modelled the existence of such a playbook. That does not make it pointless. Airliners are aware that pilots train for engine failure. The training still saves lives. Planning ahead also lets us introduce some deliberate unpredictability. Not every detail of the response needs to be public. Parts of the playbook can be transparent, such as who leads and which human rights remain non-negotiable, while concrete technical measures to isolate or neutralise specific systems could be kept offline.
Governments can already start putting the pieces of this playbook together. Frontier labs can be required to submit emergency contact details and crisis plans. National security councils can map which critical systems depend on frontier AI services and how to keep them running if those services must be paused. Emergency laws can be checked to ensure they actually cover AI infrastructure—rather than assuming only physical assets matter.
Treating superintelligence as science fiction is no longer responsible when investment in frontier systems is measured in billions, and their capabilities are rising rapidly. When AI surpasses humans on the intelligence ladder, we may not get a second chance to organize our response.
The ultimate test of AI governance will be how we behave on the day when an unbounded system starts to move faster than our institutions and when the companies that built it are no longer fully in charge.






















