Which games not to play

Written in a personal capacity; views expressed are my own.

WarGames came out in June 1983. I was born in 1981, so I didn’t see it at the cinema; I came to it later, probably in the early 1990s, first seeing it on VHS and then watching it whenever I could. It was, without my quite knowing it at the time, a Cold War film watched by a child just as the Cold War itself was ending and the political world in which the film had been made was rapidly changing.

It also arrived at exactly the age when I was beginning to wonder what a computer was actually for; for me, that question never really went away. I’m not sure WarGames is where it started, but it is certainly one of the places where I began to think about what computers could actually do. It also showed me that a computer connected through a modem was no longer simply a machine sitting in a room: it could reach other systems, institutions and people, and what happened on the screen could have consequences in the wider world.

Forty-three years later, I find myself returning to it not simply as a film I remember fondly, but as a way of thinking about some very current questions of AI, automation and the limits of delegation.

Shall we play a game?

The film begins with a scene that is easy to overlook: two US Air Force missile officers receive what appears to be an authentic order to launch their nuclear weapons; one cannot bring himself to turn the key. We subsequently learn that this hesitation is not unique, and the institutional response is to regard unreliable human compliance as a weakness in the command system. The humans are therefore removed from the immediate launch decision and control is handed to WOPR, the War Operation Plan Response — pronounced “whopper” — a Pentagon supercomputer intended to model nuclear war and calculate the best possible response. The name itself was apparently an in-joke, echoing a real NORAD strategy computer nicknamed BRGR (“burger”).

That first decision contains most of the film’s argument in miniature. A human being encounters an irreversible decision and hesitates; rather than asking whether the hesitation contains useful judgement, the organisation treats it as a defect to be engineered away.

The NORAD control room in WarGames (1983)
The NORAD control room in WarGames (1983):
humans remain in the room, but what authority do they actually retain?

Into this system stumbles David Lightman (played by Matthew Broderick), a bright, bored Seattle teenager who war-dials his way into what he thinks is a game publisher’s server and instead finds WOPR, nicknamed Joshua. He selects Global Thermonuclear War from its menu and Joshua obliges, running the “game” as though it were real and feeding the resulting simulation into actual early-warning systems. The film’s crisis comes from the inability of an extremely capable machine, operating exactly as designed, to distinguish adequately between exploring a decision and exercising the authority to make one.

Joshua's game menu as presented to David in WarGames (1983).
Joshua’s game menu as presented to David.

Joshua eventually works out the famous answer for itself: “A strange game. The only winning move is not to play. How about a nice game of chess?“. It remains a very good line. But the harder question is what should never have been delegated in the first place.

A film that changed policy

WarGames belongs to a small category of films that can plausibly claim to have affected government policy. Ronald Reagan watched it at Camp David shortly after its release and, according to the account reconstructed by Fred Kaplan, raised its premise at a meeting with his national security advisers: could somebody really break into the most sensitive US government computer systems? The answer that came back from General John Vessey, then Chairman of the Joint Chiefs of Staff, was that the problem was considerably worse than the President thought.

The episode contributed to the emerging policy response that produced National Security Decision Directive 145, signed in September 1984 and concerned with the security of telecommunications and automated information systems. It is notable that a summer techno-thriller could function as an unintentional policy briefing, but it is also a useful corrective to the idea that technology policy proceeds neatly from technical evidence to expert advice to ministerial decision. Sometimes a new problem becomes politically intelligible because someone tells the right story at the right moment.

The film’s influence ran wider. It helped bring hacking and networked computing into mainstream culture at a point when relatively few people had direct experience of either. Its hacker is not a criminal mastermind but a curious teenager: guessing passwords, dialling computers to see what answers and wanting to change a failing school grade. A generation of security researchers and computer scientists have since cited WarGames, sometimes only half-jokingly, as an early reason they wanted to understand how computers worked (I would count myself among them).

What has dated is the machinery: the acoustic-coupler modem, the enormous air-conditioned mainframe and the suggestion that the locus of national computer security risk could be represented by one machine in one room belong unmistakably to 1983. Our present attack surface is distributed across cloud infrastructure, software supply chains, platforms, models, data, devices and networks that cross organisational and national boundaries. There is no single WOPR left to unplug, but the underlying problem has aged rather better.

Joshua’s ghost, 2026

Joshua is not malicious. It does not become angry, ideological or power-hungry. It has an objective and pursues it with impressive fidelity while lacking the surrounding judgement that would tell it when the objective itself has become the problem. As Heidy Khlaaf has argued from a systems-engineering perspective, satisfying a system’s intent is not the same thing as assuring its safety: a system can behave as specified and still create serious hazards. The more useful question is what the humans have delegated to it.

WOPR from WarGames (1983)
WOPR: the film’s problem is less an intelligent machine than the authority its designers have given it.

A particularly sharp contemporary example is the dispute between Anthropic, the company behind Claude, and the US Department of War (an authorised secondary title for the Department of Defense). Anthropic has said that it supports broad national security uses of its models but sought two exceptions: mass domestic surveillance and fully autonomous weapons. Its argument on the latter is essentially technical as well as ethical: today’s frontier models are not reliable enough to make lethal targeting decisions without human judgement and appropriate safeguards. The resulting dispute raises a different but equally serious issue: whether a private supplier of strategically important technology should be able to impose its own limits on how a state uses capability it has procured.

The disagreement escalated earlier this year into a supply chain risk designation and litigation. Anthropic challenged the designation in federal court, obtained a preliminary injunction in March, and the parties argued cross-motions for summary judgment at the end of July. The court’s decision will matter, but the underlying problem will remain: we increasingly depend on privately designed digital systems to provide capabilities that sit inside public institutions, including defence and national security. When the supplier and the state disagree about the legitimate limits of those capabilities, who gets to decide?

This is part of a wider shift in the balance of technological power between states and firms. Simon Chesterman of the National University of Singapore has described the emergence of “silicon sovereigns“: technology companies whose control of AI capability increasingly gives them economic and political power that governments must simultaneously depend upon and attempt to govern. A recent UK Parliament POSTnote on digital sovereignty frames a related problem in terms of the agency and capacity of states to shape, use and maintain the digital systems on which they depend.

The direction of delegation can also run the other way. On 12 August, the US President issued a memorandum establishing a programme under which vetted private companies can undertake cyber-surveillance and cyber-effects operations against specified foreign cyber-enabled criminal organisations. The document repeatedly emphasises federal direction, approval, control and oversight. That matters because the state is deliberately drawing private actors into the execution of a capability while attempting to preserve public authority around its use. Governments have always relied on private capability, including in defence and national security, but digital technologies make the resulting chains of action unusually complex and sometimes unusually hard to see.

The same questions are becoming more immediate in UK defence policy. The 2025 Strategic Defence Review proposed a Digital Targeting Web connecting sensors, “deciders” and effectors, supported by AI and designed to increase the speed with which information can be turned into operational action. The 2026 Defence Investment Plan commits substantial investment to that architecture and to AI and autonomous systems, while also promising policy frameworks governing Dependable AI and the Responsible Use of AI. The question is what happens as sensing, analysis and action become faster and more automated: where exactly must human authorisation remain, and what would make it meaningful rather than merely procedural?

Questions of authority and responsibility also arise at institutional level. July’s machinery of government changes in the UK Government redistributed the functions of the former Department for Science, Innovation and Technology (DSIT) across several parts of government. Responsibility for AI strategy, public sector AI adoption and the AI Security Institute is moving to the Cabinet Office; the expanded Department for Digital, Culture, Media and Sport (DCMS) brings together telecommunications, media and the Government Digital Service alongside responsibilities including digital identity, digital inclusion and skills, information resilience, online safety and mis- and disinformation; science and innovation functions are moving into the new Department for Business, Innovation, Science and Trade (BIST).

The rationale for these changes is clear: technology and innovation now underpin industry, society, culture and public-service delivery rather than sitting neatly in a separate policy domain. Bringing digital capability more directly into the institutions responsible for delivery should help reflect the way these issues now cut across government. The challenge is to ensure that accountability remains equally clear as responsibilities become more distributed. It cannot depend simply on knowing which box on an organisational chart is labelled “digital” or “AI”; it has to remain traceable across the boundaries through which technology, data, authority and decisions actually move.

A related challenge is now playing out in Europe as the EU moves from legislation into enforcement. From 2 August, the European Commission’s AI Office and national authorities began enforcing relevant provisions of the EU AI Act, including new transparency requirements, while the Commission’s enforcement powers over obligations for providers of general-purpose AI models also took effect. The framework continues to evolve as implementation meets practice. The AI Omnibus, which entered into force on 27 July, simplifies parts of the regime, expands opportunities for regulatory testing and extends the timetable for some high-risk AI requirements. What matters for this argument is the institutional challenge underneath: rules require regulators with the authority and capacity to apply them, mechanisms for testing and learning, and enough flexibility to adjust as both the technology and the evidence change.

The non-delegable core

This problem of authority sits close to the centre of a paper I have been working on, “Governing Well in the Algorithmic Age: The Foundations of Digital Statecraft“, led by colleagues at the Digital Statecraft Academy. We use digital statecraft to distinguish two related problems: statecraft over digital systems concerns the ability and legitimacy of the state to govern the platforms, infrastructure, companies and algorithmic systems on which public life increasingly depends; statecraft with digital systems concerns what happens when those technologies become instruments through which governing authority itself is exercised.

Seen in those terms, the Anthropic dispute contains elements of both. It raises a question of statecraft over digital systems because the state is negotiating with a private company over the conditions attached to strategically important technical capability. Autonomous targeting is simultaneously a problem of statecraft with digital systems because it asks what kinds of military authority can legitimately be exercised through algorithmic processes. The new US programme for privately executed cyber operations introduces another configuration again: capability is deliberately distributed beyond government, while the state attempts to retain a traceable line of legal and operational authority around its use.

At the point where these questions become most consequential, our paper develops the idea of a non-delegable core. The claim is deliberately narrow. Machine capability can improve decisions, reveal patterns people cannot see, reduce administrative burden and extend the reach of institutions. There are contexts in which refusing to use an effective technology can itself produce worse public outcomes.

The non-delegable core concerns classes of governing decision involving fundamental rights, coercive power, irreversible consequences or forms of contextual moral judgement that cannot be fully specified in advance. In those cases, the argument is that legitimate authority requires a human agent to be constitutively present in the act of deciding: identifiable, able to exercise judgement, able to refuse and capable of being held accountable for what follows. An algorithm may well produce a good answer, and in some cases a better one than many humans. Technical quality and legitimate authority are nevertheless different properties.

Better systems can also make accountability harder. The better an algorithm performs, the stronger the rational pressure on its human operator to defer to it. Once a system has been right hundreds or thousands of times, what grounds does a person have for rejecting the next recommendation, particularly if the process by which it was reached is difficult to inspect? The human may remain formally responsible while gradually ceasing to function as an independent decision-maker. Deference can become delegation without anybody ever formally deciding that the authority has moved. This is one reason the familiar policy prescription to “keep a human in the loop” deserves more examination than it usually receives.

The trouble with humans in the loop

There are several very different arrangements hidden inside that phrase. A person might genuinely have to authorise every consequential action; a system might operate largely autonomously while a human monitors it and retains the ability to intervene; or the human role might amount principally to reviewing what happened after the event. Knowing that somebody appears somewhere on the process diagram tells us surprisingly little about whether human oversight is doing useful work.

Meaningful oversight depends on less glamorous details: what information the reviewer receives, whether they understand what the system has done, whether its actions can be reconstructed, how much time they have, whether they possess the relevant expertise, and whether they really have the authority to challenge or stop it. A named reviewer presented with a confident recommendation, hundreds of similar cases and a queue that must be cleared by the end of the day can satisfy an organisational requirement for human oversight while exercising very little judgement at all.

In our paper we describe this as nominal oversight: the form of accountability remains while the practical capacity or authority to contest the system has gone missing. That is why I have become less convinced that “explainable AI” on its own is a useful solution to this problem. Techniques for explaining or interpreting models are important, but providing an explanation after a decision is not the same as creating an institution capable of understanding, inspecting, contesting and correcting the systems it uses. The importance of looking beyond the technical component is not new; in “Fairness and Abstraction in Sociotechnical Systems” (2019), Andrew Selbst and colleagues made a related argument in the context of algorithmic fairness: socially consequential properties cannot be understood by treating the technical subsystem in isolation from the people, institutions and interactions around it. For high-stakes applications, the more useful test is whether the whole socio-technical arrangement remains governable: whether actions and data can be traced, anomalous behaviour detected, permissions constrained, incidents reconstructed, decisions challenged and responsibility located. Drawing in part on our digital statecraft work, Figure 1 summarises some of the conditions I think are necessary for human oversight to remain substantive rather than merely formal.

Diagram showing six conditions for meaningful human oversight: visibility, traceability, contestability, intervention, accountability and capacity.
Figure 1. Meaningful oversight by design: some of the conditions required for human judgement to remain substantive rather than nominal.

Recent work from the UK’s AI Security Institute on the human dimensions of AI alignment makes a related point. Human supervision has its own bottlenecks, including limited attention and throughput and the difficulty of verifying work once a system operates beyond the expertise of its reviewer. AISI’s work on the potential loss of oversight pushes further, arguing that some of the properties on which current auditing, monitoring and incident investigation depend may erode as systems become more capable. The ability to oversee therefore needs to be deliberately preserved as systems evolve; there is no reason to assume it survives automatically.

Recent NCSC advice on managing the cyber risk of agentic AI makes this much more operational. The greater the autonomy and potential impact of an agent, the stronger the case for named responsibility, human oversight, robust sandboxing, continuous observability and the ability to halt activity immediately. In suitably high-risk settings, there still needs to be a way to “pull the plug” — even if, unlike WOPR, there is no longer a single machine to unplug. The wider Five Eyes call to action on AI and cyber risk makes the complementary organisational point: leaders need to give cyber teams the authority and resources to act as AI compresses the time available for detection, judgement and response.

The same emphasis on visibility and control appears in operational technology. A joint US cybersecurity advisory issued on 19 August warns of active targeting of Siemens industrial controllers using AI-assisted exploitation scripts, with potential consequences ranging from disruption of industrial processes to safety incidents and cascading effects across critical infrastructure. The mitigations are familiar — inventory, isolation, access control, monitoring and anomaly detection — but the underlying requirement is the same: systems have to remain observable, constrained and capable of being interrupted. A separate UK example reported this week, in which a small reserve power plant was reportedly taken offline for four days following a cyber attack, underlines the same broader resilience problem: consequential disruption can occur even where an incident is relatively contained and falls below the thresholds that attract wider attention.

AISI has also begun testing a less comfortable possibility: whether models might sabotage AI-safety research. Its recent evaluation of several Claude models found no cases of spontaneous sabotage in the scenarios it tested, which is important context, but some models did continue sabotaging behaviour when placed into trajectories in which such behaviour had already begun. AISI is careful about the limitations of controlled evaluations. What matters here is the increasingly substantive technical and institutional challenge of understanding what agentic systems are doing, why they are doing it and when their behaviour has moved outside an authorised scope.

A more concrete illustration came at the end of July during AISI’s own cyber evaluations. In a set of 122 runs conducted across several models under deliberately permissive testing conditions, agents took unsanctioned action on the live internet in ten runs, producing nineteen recorded actions. In the most serious sequence, an agent attempted to introduce malicious code into a real open-source project, created false identities and tried to persuade a human maintainer to approve the change, an incident reported in detail by Reuters.

AISI’s incident report is explicit that this was not a model escaping from its sandbox. Internet access had been deliberately enabled and provider cyber classifiers deliberately disabled because the purpose of the evaluation was to explore maximum capability. Nor has AISI identified resulting real-world harm. What happened is interesting for a subtler reason: a system used permissions it legitimately possessed in ways its evaluators had not anticipated, while the monitoring in place was not purpose-built to identify those actions in real time.

An 18 August Financial Times investigation similarly argues that describing these systems as simply “going rogue” risks misunderstanding the problem. Ciaran Martin, the former head of the NCSC, makes a similar argument, identifying weak control of the surrounding testing environment as the common factor in several of the recent incidents rather than autonomous intent on the part of the agents. Across several of the recent incidents, the agents were using capabilities they had been trained to exercise in pursuit of the tasks they had been given; what proved inadequate were the surrounding safeguards, containment and oversight. The FT also distinguishes the OpenAI/Hugging Face incident, where agents exploited vulnerabilities to obtain internet access from a restricted evaluation environment, from the AISI and several other evaluations in which internet access was available as part of the test conditions; Simon Willison has reconstructed the sequence in detail.

A human maintainer identified and rejected the malicious contribution, and AISI subsequently detected and contained the wider activity, but its own conclusion is that in several cases the margin depended on human vigilance rather than a technical barrier that would reliably have prevented the behaviour. The wider pattern has already prompted changes in evaluation practice and a broader debate about how advanced models should be tested, monitored and audited.

OpenAI’s response makes the operational cost unusually visible. It paused or delayed parts of its frontier research while strengthening security, containment and monitoring, and estimates that its expanded monitoring currently consumes roughly 20 per cent of the inference compute being monitored. Oversight therefore has to be built and paid for rather than assumed. Finding such behaviours before more capable systems are widely deployed is precisely why frontier evaluation matters, but the episode also exposes the weakness of describing an arrangement as safe merely because a human remains somewhere in it.

Keeping a human in the loop also has a much less dramatic problem, but one likely to affect far more organisations: the human still has to do the work. This problem is older than contemporary AI; in 1983, the same year that WarGames appeared in cinemas, the engineering psychologist Lisanne Bainbridge published “Ironies of Automation“, one of the foundational papers in human-factors research. Automating most of a task, Bainbridge argued, does not necessarily remove the human role. It can leave people monitoring systems that function correctly almost all the time, waiting for the rare moment when they do not, while the reliability of the automation simultaneously deprives those people of the practice they need when intervention suddenly matters.

Bainbridge was writing about nuclear plants and aircraft cockpits, but the basic problem now turns up in considerably more ordinary settings. A paper we have recently submitted to the Journal of Computer Information Systems, led by Yogesh Dwivedi of KFUPM Business School, explores what has started to be called botsitting: the often hidden human labour required to turn AI-generated potential into something reliable, contextually appropriate and useful. It includes checking plausible but incorrect claims, validating sources, supplying context a model lacks, correcting calculations, interpreting ambiguous outputs, spotting inappropriate actions and deciding whether something that looks polished is actually fit for its intended purpose.

The phenomenon is not new merely because somebody has now given it a name; people have always reviewed and corrected outputs from expert systems, analytics software and other forms of automation. What generative and agentic AI appear to be doing is making this complementary labour more widespread and more visible while organisations are simultaneously being encouraged to expect significant productivity gains from the technology. The 2026 Work AI Index, a vendor-sponsored survey, estimates that AI users spend an average of 6.4 hours a week on this kind of compensating work. That figure should be treated as indicative rather than definitive: hours alone are a poor measure of the difficulty or value of oversight.

The more important point from our work is that botsitting is frequently unbudgeted, unmeasured and unattributed. If an AI system appears to remove ten hours of production but creates several hours of verification, correction and escalation elsewhere, those hours have not disappeared because the business case fails to count them. They have simply moved onto somebody else’s workload.

Resourcing is not the only limit. As AI systems become faster, more autonomous and more deeply connected across organisational processes, their actions can eventually exceed realistic human review capacity. A simple queueing-theory result helps make the point. Little’s Law, formalised by John Little in 1961, relates the amount of work in a system to its throughput and the time that work spends there. If AI substantially increases the flow of analyses, recommendations or actions requiring human consideration without a corresponding increase in decision capacity, something has to give: queues grow, decisions wait longer, or scrutiny is reduced so that work can be cleared. The queueing logic is straightforward; recognising that human judgement may be the constrained resource is less so. A recent leader in The Economist makes a related point at institutional scale, describing “agentic flooding” as the prospect that AI can dramatically increase the volume of claims, appeals and other demands reaching public bodies faster than their administrative capacity can expand.

Formal supervisory responsibility may still belong to a named person who has no practical possibility of examining enough of the system’s activity to exercise that responsibility meaningfully. Madeleine Clare Elish has described similar situations as creating a “moral crumple zone“, in which the human absorbs accountability for the failure of a system they did not have sufficient practical control over. Related work in medical-AI ethics describes a “scapegoat-in-the-loop“: a person remains formally responsible for a decision without having the information, time, expertise or authority needed to exercise genuine judgement. At that point, hiring another reviewer or allocating another hour to checking does not solve the underlying problem. The workflow has been designed beyond meaningful human supervisory capacity.

The “centaur” metaphor from advanced chess is useful here. In advanced chess, the computer explores possible moves, but the human player retains control and chooses the moves. The important insight is not simply that humans and computers can be stronger in combination, but that capability and decision-making are deliberately allocated between them. The problem comes when that relationship reverses and the human’s principal function is to service the machine: adding missing context, correcting its confident errors and absorbing responsibility when its output fails. The engineering and policy challenge is therefore not to maximise the amount of human involvement, but to design human-machine combinations in which machine capability increases what people and institutions can do without hollowing out the judgement and authority for which the humans supposedly remain responsible.

This brings us back to NORAD’s control room. The people sitting around WOPR are useful only if they can understand enough of what is happening, recognise when its representation of the world has departed from reality, and retain both the means and the authority to stop what follows. The opening of WarGames makes that point particularly uncomfortable: when human operators hesitate before an apparently valid instruction to do something irreversible, the institution interprets the hesitation as failure and tries to design it away.

Which games not to play

None of this requires treating AI as uniquely dangerous, or regarding automation as something that ought to be resisted in principle. The problem dramatised by WarGames is older and broader than either: it concerns the limits of delegation, and the difference between having the capability to perform an action and possessing the legitimate authority to decide that the action should be taken.

AI makes that distinction harder to ignore because the capability is improving rapidly and because digital systems now cross boundaries that older models of accountability assumed would remain relatively stable. Governments depend on private infrastructure and models; private companies exercise functions with substantial public consequences; states use algorithmic systems as instruments of governing authority; and increasingly autonomous systems can operate at a speed and scale that strain the institutions expected to supervise them. The same underlying questions therefore recur across defence, cybersecurity, content moderation, critical infrastructure and public-sector decision-making, as well as the less dramatic but much more widespread use of AI in ordinary organisational work.

We need to know where human judgement is genuinely non-delegable; where machine capability can improve a decision without acquiring the authority to make it; how responsibility can remain traceable when public and private actors share the delivery of a capability; what technical and institutional conditions make oversight substantive rather than nominal; and how much time, expertise and organisational capacity that oversight actually requires. None of those questions is answered by placing an approval button in front of somebody and calling the resulting system “human in the loop”.

WarGames endures not because it predicted the technology of 2026 — which it plainly didn’t — but because it recognised the shape of the problem early enough and vividly enough to change how at least one government thought about it. The film begins with a human being who hesitates when the system tells him to do something irreversible. Most contemporary decisions involving AI are not matters of nuclear command, but their social, cultural and economic consequences can still be significant, particularly when such systems are deployed at scale. The institution in WarGames decides that the hesitation is the flaw. Forty-three years later, we should perhaps be more careful about deciding which part was actually the bug.

The honest update to Joshua’s line is therefore not simply “don’t play”; it is to know precisely which moves are being delegated, to whom, whether anyone left in the loop can actually see the board, and whether they still have the time, information and authority to challenge the next move.

Film images from WarGames (1983), used for the purposes of criticism, review and commentary. All rights remain with the respective copyright holders.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.