Skip to content

Main Insight

The first part of our Global Red Lines for AI series explains why establishing clear international boundaries is essential not only to prevent systemic harm but to ensure AI is developed in ways that truly serve the public.

Part 1: What Are Red Lines for AI and Why Are They Important?

July 3, 2025

This article is the first part of a three-part explainer series on Global Red Lines for AI. You can find the series overview here, part 2 here, and part 3 here.

The idea of a red line is simple. In principle, we know that setting clear and reasonable limits helps keep people safe. Take road safety as an example. Regulators require car manufacturers to include vehicles with reliable, safety-tested brakes, and many vehicles are even equipped with electronic speed limiters, capping how fast they can go even if the engine could go faster. These limits collectively reduce danger and significantly improve everyone’s chances of reaching their destination safely.

So how does this idea translate to artificial intelligence? As AI capabilities rapidly advance, we risk crossing into hazardous territory if we fail to establish guardrails now. Like cars, AI offers remarkable opportunities, but without well-defined limits, it presents serious dangers. Red lines can serve as the “rules of the road” for AI: boundaries that ensure these technologies don’t cause harm and remain aligned with the public interest.

This explainer, part one of a three-part series, dives into what red lines for AI are and why it’s crucial to address them today.

What is a red line?

In basic terms, a red line is a limit that shouldn’t be crossed. We rely on red lines in many areas of life, like setting maximum levels for toxic chemicals to protect workers’ health, or capping pollution to protect the environment. While these red lines don’t eliminate all risks, they define what society agrees is unacceptable.

Some specific examples of international red lines include:

Examples of International Red Lines in Other Fields
FieldExplanationSource(s)
Ozone layer protectionProhibition of the production and consumption of ozone-depleting substances, or man-made chemicals that severely harm the Earth’s protective ozone layer.The Montreal Protocol on Substances that Deplete the Ozone Layer (1987)
Human cloningProhibition of reproductive human cloning, or creating a human being genetically identical to another human being alive or dead.Council of Europe’s Oviedo Convention (1997)
United Nations Declaration on Human Cloning (2005)
Biological weaponsProhibition of the development, production, acquisition, transfer, stockpiling and use of biological and toxin weapons.Biological Weapons Convention (BWC) (1972)
Cloning of recombinant DNAs Prohibition of the cloning of recombinant DNAs derived from highly pathogenic organisms.Asilomar Conference on Recombinant DNA (1975)

Table 1: Examples of international red lines in other fields

What is a red line for AI?

There is no universally agreed upon definition of “AI red lines” but broad agreement can be seen regarding their key characteristics. The OECD defines AI red lines as a “threshold defined in terms of unacceptable model capabilities regardless of mitigations,” while the World Economic Forum refers to them as “specific boundaries that AI systems must not cross.” 

Red lines for AI
For the purpose of this piece, we define red lines in AI governance as specific, non-negotiable prohibitions on certain AI behaviors or AI uses that are deemed too dangerous, high-risk, or unethical to permit. These boundaries are intended to protect the survival, security, and liberty of humankind.

AI red lines can fall into two categories:
1. AI behaviors: limits on certain behaviors that AI systems should not exhibit (e.g., developers must prove that their systems will not exhibit self-replication or improvement without human control, even if the systems are technically capable of doing so).
2. AI uses: limits on how humans can use the AI system (e.g., a prohibition on using AI to manipulate or surveil children, even if technologies enabling doing so exist)

In practice, different terms are often used to describe what are essentially “red lines” for AI. While these terms vary slightly in meaning and emphasis, they share a common goal: identifying behaviors or uses of AI that are considered too dangerous, unethical, or harmful to be allowed. Common examples include “risk thresholds” which refer to specific levels of risk for which there are specific consequences; “unacceptable risks” which highlight outcomes that are not tolerable under any circumstances; and “prohibitions” which make an explicit ban. Though the language may differ across legal, technical, and policy contexts, these concepts all reflect a growing recognition that some AI behaviors and uses should be off limits.

What are some specific examples of red lines for AI? 

Some uses and behaviors of AI pose such serious risks that they are increasingly seen as non-negotiable. Below are a few examples of AI red lines that many experts and governments around the world are beginning to coalesce around. Part 2 of this series examines concrete policies where these red lines are starting to take shape.

How these red lines are enforced may vary depending on the specific threat. Options include licensing mechanisms that block market access for developers who can’t demonstrate their systems are safe, or penalties for violations.

Potential Red Lines for AI
Red LineExplanationCategoryRelevant Activities
Child ExploitationBan the use of AI systems designed or used to manipulate, surveil, or exploit children’s vulnerabilities.AI useIn 2023, the UN adopted the Resolution on the Rights of the Child in the Digital Environment, which “urges States to prohibit the unlawful digital surveillance of children, (…) to work towards enabling secure communications and the protection of (…) their privacy”, amongst other provisions. Private sector initiatives to protect children are also emerging, such as the Tech Coalition’s work on safety-by-design mechanisms protecting misuse of generative AI in relation to children.
Lethal Autonomous Weapon Systems (LAWS)Ban the use of AI in weapons systems that autonomously select and engage human targets without meaningful human control.  AI useA new international treaty on Lethal Autonomous Weapon Systems is under discussion at the UN and is gaining momentum.
Social ScoringBan the use of AI systems for systematically monitoring individuals or assigning “social credit” that affects rights or access to services.AI useTitle II of the EU AI Act, focusing on prohibited AI practices, outlines a range of AI systems that are forbidden within the European Union. These include the assessment of individuals based on social behavior or personality traits. UNESCO AI Ethics Recommendation also highlights that AI systems should not be used for social scoring or mass surveillance purposes.  
Autonomous Self-Replication and Uncontrolled Self-ImprovementBan AI systems from autonomously copying or improving themselves without human oversight.AI behaviorThe International Dialogue on AI Safety (IDAIS) Consensus Statement on Red Lines in Artificial Intelligence highlighted autonomous replication and improvement as key red lines. The G7 Hiroshima Code of Conduct also acknowledged the risk from models of making copies of themselves or “self-replicating” or training other models. Additionally, the Asilomar AI Principles addressed the issue of recursive self-improvement.
Power SeekingBan AI systems that are capable of taking actions aimed at unduly increasing their own influence, access to resources, or control over people or systems.AI behaviorInternational scientists under the IDAIS Consensus Statement on Red Lines in Artificial Intelligence also identified power seeking as a capability that should be prohibited.
Autonomous CyberattacksBan AI systems capable of autonomously conducting cyberattacks.AI behaviorIDAIS Consensus Statement on Red Lines in Artificial Intelligence states: “no AI system should be able to autonomously execute cyberattacks resulting in serious financial losses or equivalent harm.”

Table 2: Potential red lines for AI

Who wants red lines for AI? 

Momentum for establishing AI red lines is rapidly building among experts and the public alike.

In March 2024, global AI scientists gathered in Beijing for the International Dialogue on AI Safety (IDAIS), where they jointly called for red lines in AI development to prevent catastrophic and potentially existential risks.

As part of the official process for the AI Action Summit held in Paris in February 2025, The Future Society conducted a global consultation with over 10,000 citizens and more than 200 expert organizations across five continents. One of the top priorities identified by experts was the need to establish “clear and enforceable red lines for advanced AI development.”

Civil society organizations (CSOs) are also pushing this issue to the forefront. In a February 2025 poll conducted by The Future Society, 44 CSOs ranked their highest priority as “establishing legally binding ‘red lines’ prohibiting high-risk or uncontrollable AI systems incompatible with human rights.”

Why are global red lines for AI important?

Establishing global red lines is no longer just desirable; it is necessary. On a global level, we must act to define and prohibit a set of AI behaviors and uses that pose disproportionate, cross-border risks. These red lines can serve as a critical backstop in global governance: setting clear prohibitions on developments we agree must not proceed under any circumstances, regardless of commercial incentives or national interests.

There are three core reasons why such global boundaries matter:

1. AI risks are systemic and transnational.

As AI is increasingly embedded in critical systems, daily life, and decision-making processes, the world is becoming more dependent on these technologies. This growing reliance means that when harm occurs, the consequences can be far-reaching and deeply disruptive. As the International AI Safety Report 2025 emphasizes, “system flaws can have a rapid global impact: When a single general-purpose AI system is widely used across sectors, problems or harmful behaviours can affect many users simultaneously. These impacts can manifest suddenly, such as through model updates or initial release, and can be practically irreversible.” 

Importantly, AI risks do not respect borders. Regardless of where a system is developed or deployed, its impacts can quickly spill over into other countries, similar to financial market shocks that trigger global recessions or the uncontrolled release of an engineered pathogen leading to a worldwide pandemic. These risks are often interrelated: a failure or misuse in one domain can trigger cascading effects in others, amplifying the harm worldwide.

2. The current global landscape rewards speed of AI development over safety. 

Without global coordination on AI red lines, we risk a “race to the bottom,” where countries and companies prioritize speed over safety and the protection of fundamental rights. This dynamic is already playing out with the emergence of AI systems that exhibit agent-like capabilities, including the ability to reason, make plans, and take actions in both digital and physical environments. The pursuit of artificial general intelligence (AGI), driven by a handful of powerful actors with immense commercial and strategic incentives, has only intensified these pressures, often sidelining safety. This isn’t necessarily due to bad intentions; it’s a reflection of the current incentives, which reward rapid progress over caution and disclaim liability. 

In a context shaped by both corporate and geopolitical competition, globally agreed upon red lines for AI could serve as a minimum baseline to define what must not be done. In the absence of a broad, universal definition of safety, red lines offer a clear way to define compliance by marking obviously unsafe and unacceptable behaviors. Even major tech companies recognize this need: for example, in 2023, Microsoft asked for “safety brakes” when risks become unacceptable. Reflecting growing consensus, in 2024 at the Seoul AI Safety Summit, 27 countries and the EU committed to establish shared thresholds of risk beyond which AI labs won’t release their models. 

3. Enforceable boundaries are critical for public trust, so we can actually use AI for good.

Lastly, if advanced AI systems are to truly serve the public interest, people must have confidence that their development is subject to meaningful constraints. Normative principles and voluntary commitments are not effective enough. AI users need informed trust. Binding red lines can signal that certain behaviors and uses are out of bounds. When those limits are clearly defined, globally agreed upon, and enforced, they can help build the legitimacy of AI governance efforts and ensure continued accountability and oversight. Building public trust this way is essential if we want societies to embrace and benefit from AI, rather than fear or resist it.

This all sounds good in theory. But what about in practice?

In Part 2 of this series, we expand on where red lines for AI already exist or are starting to take shape. Drawing from binding treaties and corporate policies, we highlight real-world examples that could serve as a solid foundation for global boundaries against specific AI behaviors and uses.

Related resources

What compute on European soil might buy Europe and what it depends on

What compute on European soil might buy Europe and what it depends on

Across Europe, there is growing appetite for locating large compute capacity at home. This post maps what the benefits' proponents claim such a buildout might bring and the key open questions these claims stand or fall on.

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

Buyer Beware: What AI-Enabled Weapons in Africa Reveal About Verification

AI rules cannot reliably protect people when compliance cannot be checked. In a new CIGI policy brief co-authored by George Gor (TFS) and Kofi Yeboah (Mozilla), AI-enabled weapons in Africa serve as a case study of how procurement and regional verification can test supplier claims, reduce risks to civilians and...

The Case for Cross-Border AI Incident Infrastructure

The Case for Cross-Border AI Incident Infrastructure

AI incidents are scaling fast, and coordinated global governance is lagging behind. This report proposes addressing this challenge through the development of internationally-distributed incident management infrastructure. Our recommendations aim to enable governments, multilateral bodies, and frontier AI companies to jointly detect, prepare for, and respond to AI incidents across jurisdictions.

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

Determining the State of the Art in General-Purpose AI Risk Management: From Code to Practice

The EU's AI Act and Code of Practice requires providers of the most advanced AI models to meet the ‘state of the art’ (SOTA) in safety and security. In a new policy memo, we argue that SOTA is best understood as a process-driven concept, advanced by the broader expert ecosystem.

EU AI Act meets AI Agents

EU AI Act meets AI Agents

Highlights from Tech Policy Press article “The EU AI Act is Not Ready for Agents,” examining how the EU AI Act applies to AI agents and governance challenges.

Future-Proofing EU AI Gigafactories: Four Design Imperatives

Future-Proofing EU AI Gigafactories: Four Design Imperatives

The EU's AI Gigafactory initiative is its largest planned compute investment to date. Our new memo identifies four imperatives that the initiative must address to deliver on Europe's frontier AI ambitions.