Publications
Rethinking AI Policy: The Case for Integration and Protocol Governance
Huma Rehman
Analysis Series
Analysis/0061/August/2026/London-Dialogue. 06 August 2026
Author: Huma Rehman
The dominant Artificial Intelligence (AI) policy debate has long focused on two points: the capabilities of foundation models (what AI systems can do and offer) and end-use applications (what actors do with them). Regulators debate training data, compute thresholds, and dual-use potential at one end, and sector-specific risks such as deepfakes, autonomous weapons, and algorithmic discrimination at the other. What this framework neglects is the consequential domain in between: the harness layer, which governs how AI systems are deployed and constrained, and the protocol layer, which governs how AI systems communicate with other systems, sensors, and decision-makers. In high-stakes domains, this may be the significant governance gap of all.
What Are the Integration and Protocol Layers?
The integration layer refers to the architecture of constraints, permissions, and oversight mechanisms wrapped around an AI system at deployment: authorisation rules determining what an AI can initiate autonomously versus what requires human confirmation; threshold parameters that trigger escalation, and logging and audit trails that make AI behaviour reconstructable after the fact. A capable AI system without a well-designed integration is like an automated system without governors: high output, low predictability.
The protocol layer refers to the communication interfaces between AI systems and their operational environments, including machine-to-machine messaging formats, handshake procedures between AI subsystems, and the standards governing how AI-generated recommendations reach human decision-makers or other automated systems. In military command networks, critical infrastructure, and financial systems, the protocol layer determines not just what information flows but also how fast, in what format, and with what priority.
These layers are not mere technical details. They are where policy now lives and has consequences.
Why Capabilities-Focused Policy Falls Short
Mostly, AI policy debate centres on the foundation-model level: should certain capabilities be restricted, certain training data be prohibited, or compute ceilings be imposed? These are legitimate questions, but focusing primarily on model-level governance assumes that an AI system’s risk profile is determined by what the model can do in the abstract, rather than by how it is embedded and constrained in a specific operational context.
This assumption fails in practice. A highly capable system with strong integration constraints, mandatory human authorisation, interpretable decision logs, and enforced escalation pathways poses a categorically different governance challenge than a moderately capable system with no meaningful integration, deployed where its outputs directly trigger physical, financial, or strategic action. The Chornobyl disaster was not primarily a failure of reactor design; it was a failure of the operational protocols governing how the reactor was managed under technical crisis. The same logic applies to AI systems in high-stakes environments.
The Protocol Layer as a Crisis Variable
The protocol layer becomes especially critical in fast-moving, multi-system environments, precisely where AI is being adopted most aggressively. Specifically, in military applications, how an AI-enabled sensor system communicates its threat assessments to an autonomous response platform is not merely a technical interoperability question; it determines whether human judgement can be meaningfully preserved within decision cycles increasingly driven by algorithmic data processing.
This distinction matters because scholarship on algorithmic decision-making emphasises that meaningful human judgement, not just nominal human role, is crucial for accountability in automated systems. Similarly, AI-enabled threat detection systems are designed to enhance situational awareness and response speed in cybersecurity and defence contexts, but the architecture connecting detection to response shapes whether human oversight remains substantive or merely symbolic
For instance, the India-Pakistan confrontation of 2025 illustrated this vividly. As both states deployed AI-enabled surveillance and electronic warfare platforms, the risk of misattribution, one system’s output misread by another as confirmed hostile action, grew with the proliferation of autonomous sensing. The danger was not that any single AI model was too capable but that communication protocols between systems had no standardised uncertainty-flagging mechanisms, no mandatory latency floors before recommendations reached human commanders, and no interoperability that might have enabled inadvertent-escalation hotlines to function.
Governance frameworks that focus on model capabilities cannot address this. Protocol-level risks require protocol-level governance.
Where Global Governance Instruments Fall Short
This model-centric bias is not confined to national debates; it is embedded in the emerging architecture of global AI governance itself. The EU AI Act classifies risk largely by application domain and model capability tier. The Bletchley Declaration and the subsequent Seoul and Paris AI Safety Summits have concentrated on frontier-model risk evaluation and voluntary developer commitments. The OECD AI Principles and the G7 Hiroshima Process emphasise transparency at the level of the AI provider, not operational deployment. Even the UN Group of Governmental Experts on Lethal Autonomous Weapons Systems remains largely deadlocked on definitional questions about the weapon system itself, rather than the authorisation architecture and communication standards surrounding its use.
None of these instruments meaningfully addresses integration or protocol requirements. A genuinely global governance layer would need: binding minimum standards for human-authorisation thresholds in consequential autonomous decisions, modelled on nuclear command-and-control practice; interoperable, internationally agreed uncertainty-flagging and system-identification protocols for military and critical-infrastructure AI, akin to hotline arrangements in nuclear crisis management; auditable logging requirements that survive jurisdictional boundaries and allow post-incident reconstruction in multilateral fora; and confidence-building measures between rival AI-adopting states, such as South Asia’s nuclear dyad, to reduce the risk that opaque protocol layers convert sensor ambiguity into inadvertent escalation. Absent such requirements, global summits will keep certifying that frontier models are individually ‘safe’ while the operational seams between systems, where crises originate, remain ungoverned.
What Integration and Protocol Governance Would Look Like
A serious policy agenda at these layers would involve several things. First, mandatory integration standards for AI systems in consequential domains: prescribed authorisation architectures, human-in-the-loop requirements calibrated to decision irreversibility, and minimum logging standards that make accountability reconstructable. These are not capability restrictions but deployment conditions, similar in logic to aviation airworthiness requirements, which govern not an aircraft’s aerodynamics but the systems and procedures that make it safe to operate.
Second, protocol standardisation initiatives for high-risk multi-system environments. Just as nuclear states eventually developed AI-specific communication protocols, including hotline channels and AI-dedicated signalling conventions, to manage crisis stability risks, AI-intensive environments need mutually agreed standards for uncertainty and crisis communication, system identification, and escalation flagging. This is a multilateral governance challenge in military contexts and a regulatory standard-setting challenge domestically, but in both cases the governing object is the protocol, not the model.
Third, integrating a protocol oversight-audit mechanism as a regulatory instrument. Rather than evaluating foundation models in isolation, which tells regulators relatively little about operational risk, regulators could require demonstration of integration integrity and protocol compliance as conditions of deployment. This shifts the audit object from the AI system’s often-opaque internal workings to its operational envelope, which is more tractable, and translates far more readily into binding international agreements than model-level restrictions do.
The Governance Payoff
Redirecting policy attention toward integration and protocol layers offers something the current debate has struggled to produce governance measures that scale across capability levels, use cases, and jurisdictions without requiring agreement on contested model-level questions. States that cannot agree on training data restrictions may still agree on a global preliminary reference framework working draft to highlight human authorisation requirements for AI systems’ integration into specific systems, mainly defence capabilities. Regulators who cannot audit transformer weights can audit authorisation logs.
The AI policy debate has spent years asking what AI systems are capable of. It is a need of the hour with equal rigour: how AI integration and protocols affect and connect to each other, and what binding international requirements govern both. That is where the next generation of AI-driven crises will unfold and where effective global governance must now be built or considered.
The four-layer map makes the argument of this article. Policy attention clusters at the two ends: the model layer, where capabilities are debated, and the application layer, where end-use harms are litigated; integration and protocol appear largely unaddressed by binding rules. Yet it is precisely in that middle ground, in how systems are authorised to act and how they communicate with one another, that operational risk accumulates most acutely during a crisis. Rethinking AI policy means closing that gap: extending governance inward, to the layers where consequential decisions are actually shaped, rather than continuing to legislate only at the edges.
Huma Rehman
Related posts
The Maritime Blockade and the Strategic Calculus of the U.S., Iran, and Israel Toward a Renewed Armed Confrontation
Understanding Asim Munir’s Doctrine: Regime Security in Place of a National Goal
The Data Dilemma: Navigating the AI Systems Matrix
The Anatomy of a Shortfall: Europe’s Nine Capability Areas and the Lessons for Pakistan
From Quiet Diplomacy to Attempted Maritime Security Governance: Oman’s Role and Limits in the 2026 Strait of Hormuz Crisis
Anatomy of Asymmetry: How a Weaker State Converts Vulnerability into Leverage
Integration for Stability: The SDF’s Dissolution and Syria’s Security Order
The Western Flank Unravelled: Cross-Border Militancy, TTP Resurgence, and Afghan Taliban Governance
The Time of Guards Tank Divisions is Gone, or Maybe It is Not?
Re-pricing Israel’s Corridor: The Mecca Alliance and IMEC
The SCO at 25: From Regional Security Mechanism to Platform for a Multipolar Eurasia
Imran Khan: The Last Hope of a Nation
London Dialogue — Founding Statement
Publication Categories
- Analysis (85)
- Book Review (1)
- Commentary (4)
- Essay (7)
- Journal (0)
- Journal Article (0)
- Policy Brief (5)
- Research Article (2)
- Research Report (3)
- Working Paper (0)
- Young Writers Corner (0)