Start your day with intelligence. Get The OODA Daily Pulse.

Home > Analysis > OODA Original > Does the World Need an International Software Governance Treaty?

Does the World Need an International Software Governance Treaty?

There is little doubt that software plays an important role in modern society as it runs financial systems, manages electricity grids, facilitates communications, supports healthcare, controls transportation, and increasingly drives military and government operations. Most of this infrastructure is overlooked by the average user. It works quietly in the background, until it does not. That dependence reveals an uncomfortable reality, as a software vulnerability can disrupt organizations globally, and can impact operations faster to which governments can respond. And increasingly, software itself can be produced by artificial intelligence systems that may generate code faster than humans can evaluate it.

Therefore, the question is not whether software requires governance; it already does. The larger question is whether the existing national regulations, industry standards, and voluntary practices are sufficient for an infrastructure that has become global. And it’s become abundantly clear that question is a resounding, “no,” underscoring the need for a common international framework establishing baseline expectations for software security, supply-chain integrity, vulnerability disclosure, and accountability.

Software Is Infrastructure

The International Telecommunication Union (ITU) has recognized the growing significance of software supply-chain security, noting that vulnerabilities and compromises within software supply chains can have potentially devastating and long-term consequences. This is largely due to the fact that the line between software and critical infrastructure is increasingly being erased.

The software supporting these systems is often assembled from components developed and maintained around the world. A commercial application might incorporate open-source libraries maintained by volunteers, proprietary code developed by several vendors, cloud services hosted in another jurisdiction, and application programming interfaces operated by companies somewhere else. In such an environment, the customer sees one application while the supply chain sees multiple dependencies. An attacker sees potential and opportunity.

Artificial Intelligence Has Changed the Equation

Artificial Intelligence (AI) introduces another variable into an already complicated environment.

AI-assisted coding has moved rapidly from novelty to mainstream development practice. In February 2026, The San Francisco Standard examined the growing ability of AI systems to perform software-development tasks and the implications for the traditional role of software engineers.

The obvious concern is employment. But cybersecurity should be asking a different, very important question – who is accountable when AI-generated code creates a vulnerability? Just because AI can generate code quickly does not mean the code is secure. Notably, there has been research conducted on AI-generated programming that has identified vulnerabilities and distinct defect patterns in AI-produced code, reinforcing the need for security testing and human oversight.  This creates a potential problem for organizations that are under pressure to produce software faster and cheaper. Invariably, they will rely on AI to handle large portions of code development and then have humans review what’s produced. While seemingly a logical oversight function, problems can arise when development is going at a pace that human quality control can’t keep up with. This is potentially an unsustainable security model effectively forcing the human element to accept the AI-generated code without fully examining it.

Another inherent concern is that reliance on AI invariably starts to replace human expertise. If AI is engaged in programming, future generations of developers may have less opportunities to learn how systems are built from the ground up. And while the obvious risk is that humans are cut out of the software development process, the larger risk is that organizations may lose the necessary technical expertise to challenge AI systems. In this instance, AI could make software development more productive while at the same time making its security assurance more difficult.

The Supply Chain Problem

AI-generated software is only one piece of the problem. The software supply chain is another factor that needs to be considered. Only a small percentage of modern software codebase is created from scratch, with the majority relying on pre-existing open-source components, according to one source. The compromise of one component can therefore affect thousands of downstream organizations.

And while NIST has already developed guidance addressing software supply-chain security, including software verification, supplier risk management, vulnerability management, and software bills of materials, supply chains are global. A software component maintained in one geographic region can be incorporated into an application developed in another and used by an organization in still another. That is how easy how a vulnerability in one location can become a multinational problem very quickly, a point stressed in the ITU’S report on software supply chain security that recommended international coordination and technical standards to address this concern.

What Washington Can Do

The United States is positioned to lead this discussion, but leadership should begin with coalition building rather than immediately proposing a treaty.

Establish an international software security initiative. The United States should work with the G7, NATO, OECD, Indo-Pacific partners, and international standards organizations to establish common principles for software security and supply-chain integrity. The goal should be interoperability, encouraging governments to implement their own regulations while adhering to a common security baseline.

Software ownership and custody should become an international priority. Organizations should be able to determine where software originated, what components it contains, who maintained those components, and whether the software was altered during development or distribution. As NIST guidance suggests, software bills of materials, vendor risk assessments, and open-source software controls should become increasingly common expectations for software supporting critical systems.

AI-generated software needs its own security baseline. The United States should promote international principles requiring organizations to maintain accountability for production software, conduct appropriate security testing, and apply additional verification to AI-generated code especially that which is used in critical systems. Just because AI wrote it shouldn’t be an excuse for lack of accountability.

There needs to be common vulnerability-disclosure expectations. International partners should be encouraged to establish compatible processes for reporting serious vulnerabilities, coordinating disclosure, notifying affected organizations, and maintaining security support for software that remains operationally important.

The Road Ahead

An international treaty addressing every software developer and every application is not feasible, but a practical shared understanding of what trustworthy software looks like is a necessary undertaking. That means knowing where software comes from, what components it contains, when vulnerabilities are discovered, who is responsible for addressing them, and increasingly, whether artificial intelligence played a role in creating the code. Fortunately, international organizations like the ITU have begun moving in this direction, but more needs to be done and at a quicker pace. This is where the United States can immediately assume a leadership role.

Washington has the technology sector, cybersecurity expertise, standards organizations, diplomatic relationships, and international influence necessary to bring governments and industry together around a common framework. Waiting for the next major software supply-chain compromise to create the political momentum for action would simply repeat the reactive cycle that has impacted cybersecurity for years. The challenge is no longer simply securing computers; it is securing the software ecosystem upon which modern society depends. Because the bottom line is that software may be written anywhere, but its consequences can be everywhere.

Emilio Iasiello

About the Author

Emilio Iasiello

Emilio Iasiello has nearly 20 years’ experience as a strategic cyber intelligence analyst, supporting US government civilian and military intelligence organizations, as well as the private sector. He has delivered cyber threat presentations to domestic and international audiences and has published extensively in such peer-reviewed journals as Parameters, Journal of Strategic Security, the Georgetown Journal of International Affairs, and the Cyber Defense Review, among others. All comments and opinions expressed are solely his own.