TL;DR for operators
Any high-stakes agreement needs an answer to a practical question: what evidence should be enough to loosen the rule, and who gets to decide? Across eight comparable treaty regimes, Lennart Finke’s International Agreements to Limit Frontier AI: Objectives and Exit1 finds no concrete rule that automatically ends an agreement once its substantive objective has been achieved; exit instead relies mainly on unilateral withdrawal or fixed duration. :contentReference[oaicite:0]{index=0}
That leaves frontier-AI agreements with a substantive risk-governance problem. The paper evaluates rules for loosening restrictions by accuracy, verifiability, preservation of sovereignty, and precedent. Fixed time limits score well on verifiability and precedent but poorly on whether they track reduced AI risk; preparedness-based conditions better track whether catastrophic-risk pathways have been addressed but are harder to verify and have little precedent.
The proposed response is staged rather than a simple sunset clause. A compute cap would operate for five years while a new organization develops preparedness-based conditions covering rogue AI, catastrophic misuse, and catastrophic societal developments. Parties would then approve those conditions, extend the process by up to two years, or terminate the agreement. The five years are therefore not a safety threshold.
For frontier labs and infrastructure operators, the operational implication is that treaty compliance may eventually require both monitoring current development restrictions and producing credible evidence that could justify loosening them. That inference remains conditional on the paper’s compute-cap scenario, geopolitical assumptions, and still-underspecified preparedness criteria.
Treaty exit is part of the risk model
Any high-stakes agreement eventually faces two questions: what evidence should be enough to loosen the rule, and who decides when that evidence is sufficient?
Existing treaty practice gives less guidance than one might expect. Across eight regimes covering nuclear arms, biological weapons, and environmental coordination, Finke finds no concrete provision that automatically voids an agreement once its substantive objective has been achieved. Exit mechanisms instead tend to rely on unilateral withdrawal or fixed duration.
That precedent is useful for preserving state autonomy, but it does not solve the frontier-AI problem. If restrictions are imposed because advanced-AI development is considered dangerously premature, elapsed time alone is a weak indicator that the underlying danger has disappeared.
The paper calls the rule for moving an agreement into a less restrictive state a relaxation condition. That framing shifts attention from the legal act of leaving a treaty to the evidence that should justify reducing its constraints.
The paper evaluates such rules against four desiderata:
| Criterion | What the paper asks |
|---|---|
| Accuracy | Does the condition track whether advanced-AI risks have actually been adequately addressed? |
| Verifiability | Can parties determine credibly and unambiguously that the condition has been met? |
| Preservation of sovereignty | Can states still respond to changed circumstances or assessments? |
| Precedent | Does successful prior treaty practice support this kind of mechanism? |
For the paper’s assumed strategic setting, the ordering is:
This ordering is a policy judgment, not an empirically estimated weighting.
The easiest rule to administer can track the wrong thing
Table 1 makes the core trade-off visible.
A fixed time limit receives High ratings for verifiability and precedent but Low for accuracy. Governments can tell when five years have passed. What they cannot infer from the calendar is whether alignment, misuse prevention, societal resilience, or other relevant safeguards have become sufficient.
Progress in preparedness receives the paper’s only High rating for accuracy. Here, restrictions would be relaxed after evidence indicates that relevant catastrophic-risk pathways have been addressed. The paper gives this approach only Medium verifiability and Low precedent.
Those ratings are qualitative judgments rather than measured scores. Their analytical purpose is to show why there is no dominant exit mechanism under all objectives.
Other options expose different weaknesses. Extraordinary-event clauses preserve sovereignty but rate poorly on accuracy and verifiability. The absence of AI-related incidents is easier to verify, yet the absence of observed failure does not necessarily demonstrate preparedness. A global AI-development project poorly on accuracy and verifiability. The absence could create a clear institutional event but would reduce national autonomy.
For businesses, the difference affects what becomes predictable. A fixed deadline makes capital planning easier because the regulatory endpoint is known. A preparedness-linked rule makes the endpoint contingent on evidence, assessment, and political agreement. That can create coordination costs, but it also ties relaxation more closely to the reason restrictions existed in the first place.
Five years is a design window, not a safety threshold
The paper does not solve the trade-off by declaring that restrictions should expire after five years.
Instead, it argues that negotiators may not yet know how to specify a sufficiently robust future safety threshold. Restrictions can begin first, while a dedicated organization uses the restricted period to improve the criteria for ending or relaxing them.
This is the paper’s deference to a later specification: establish the initial constraint now, then define more detailed exit conditions after additional research, evidence gathering, and coordination.
The concrete recommendation is a five-year initial agreement under a training-compute cap. During that period, a new organization would develop preparedness-based conditions addressing three broad categories: rogue AI, catastrophic misuse, and catastrophic societal developments.
After five years, the parties would need to approve the resulting conditions. If they cannot agree, they could extend the process for two years or terminate the agreement.
The architecture separates two uncertainties that are difficult to solve simultaneously at treaty signing: whether an immediate development restriction can be monitored, and what future evidence should count as sufficient preparedness.
Firms may need to prove preparedness, not only compliance
The paper directly analyzes treaty architecture, not corporate compliance programs. The business implications therefore require an additional inference.
For frontier labs, a preparedness-linked exit regime could make evidence production economically consequential. Internal thresholds for alignment, interpretability, misuse robustness, red-teaming, or contingency planning would matter internationally only if they could contribute to conditions that states regard as sufficient, credible, and resistant to manipulation.
That is a higher standard than demonstrating that a company has a safety process.
For data-center operators and compute-governance stakeholders, infrastructure timelines also enter treaty design. The paper recommends allowing individual withdrawal after extraordinary events with four months’ notice, motivated principally by a scenario in which a capable non-signatory begins building frontier-scale compute capacity.
The four-month period is linked to current assumptions about frontier data-center buildout time. If infrastructure can be assembled materially faster, or if expansion becomes easier to predict and constrain, the appropriate notice period changes.
This gives operators a concrete boundary: infrastructure observability and buildout speed can influence not just enforcement of compute limits, but the amount of strategic response time an agreement must preserve.
The architecture travels better than the numbers
The paper’s recommendations are scenario-dependent.
Its main case assumes a treaty among NATO states and China, a cap on training compute, less capable but still relevant non-signatory states, and relatively weak direct enforcement. Reputational and diplomatic incentives therefore carry substantial weight.
Preparedness criteria also remain unresolved. The paper does not identify a single alignment metric, interpretability threshold, incident rate, red-team result, or resilience measure that would independently establish that unrestricted advanced-AI development is safe.
That gap is central rather than incidental. The staged design creates time and institutional capacity to develop better criteria; it does not demonstrate in advance that such criteria will prove technically robust or politically acceptable.
The reusable idea is therefore the separation of restriction now from evidence-based relaxation later. The five-year period, two-year extension, and four-month withdrawal notice should be read as parameters derived from a particular strategic setting, not default values for frontier-AI governance.
Exit rules should be designed before they are needed
Restrictions on frontier AI create two symmetric policy risks: ending them before the underlying danger has been reduced, and making them so difficult to relax that sovereign states hesitate to enter or remain in the agreement.
Finke’s contribution is to make that tension explicit. Treaty precedent supplies workable models for withdrawal and duration, but comparatively little guidance for tying relaxation directly to successful risk reduction.
For firms exposed to future compute governance, this means treaty design could shape more than the amount of compute available for training. It could determine what preparedness evidence must exist, who must be able to verify it, and how much discretion remains when geopolitical conditions change.
The paper does not provide the final preparedness threshold. It provides an institutional design for reaching one while restrictions are already in force. Whether that process can produce conditions that are technically credible and politically acceptable remains the decisive uncertainty.
Cognaptus: Automate the Present, Incubate the Future.
-
Lennart Finke (2026). International Agreements to Limit Frontier AI: Objectives and Exit. arXiv:2607.16224. https://arxiv.org/abs/2607.16224 ↩︎