Before the first AI crisis, Washington and Beijing need a habit of talking

September 25, 2026

Presidents Trump and Xi wrapped their two-day summit in Washington without a formal AI agreement. But before the two leaders sat down, U.S. officials announced plans for an incident line on AI risk. For the NatSpecs blog, IST’s Steve Kelly, Sylvia Mishra, and Catherine Murphy unpack what this means for the future of U.S.-China AI risk reduction efforts.
President Donald J. Trump joins Xi Jinping, President of the People’s Republic of China, at the start of their bilateral meeting Saturday, June 29, 2019, at the G20 Japan Summit in Osaka, Japan. ( Official White House Photo by Shealah Craighead)

Trump and Xi’s summit put AI on the agenda. The new bilateral dialogue, and the incident line it will negotiate, will work only if they’re built for routine use, not just emergencies.

Presidents Trump and Xi wrapped up their two-day summit in Washington today without a formal AI deliverable, though Beijing’s readout had Xi calling for the two sides to continue their AI dialogue and “jointly prevent the misuse and abuse of AI.” The week’s most concrete AI step came before the two leaders ever sat down. Following talks in New York with Vice Premier He Lifeng, Treasury Secretary Scott Bessent announced the U.S. proposal to open “an incident line so that we have constant communications.”

Establishing an incident line would be a significant step in the right direction. The two governments have formalized a U.S.-China AI dialogue, slated to meet next in Shenzhen in about two months. An important early step will be agreeing on the leading AI dangers, which Bessent described as “uncontrollable agents” and non-state actors using AI to gain cyber and biological weapons capabilities. The incident line is another potential outcome of that process. Whether any of it amounts to much depends on whether the dialogue becomes a standing habit or just another summit accessory.

Neither leader wants an AI treaty. Trump has rejected any “globalist scheme” to control AI. Xi, who in July called for early-warning and emergency-response systems to keep AI “always under human control,” resists outside constraints on China’s own development. The dialogue asks neither side to slow down or give anything up, only to agree on what’s dangerous and to alert each other about AI-related security incidents. This step is a critical risk-reduction and confidence-building measure, one that can help clarify misperceptions and lower the odds of miscalculation, without limiting what either side can build.

To make the dialogue work, Washington and Beijing should do four things:

  1. Build the incident line for routine use. Model it on the U.S.-Russia National Nuclear Risk Reduction Centers, adopt shared definitions and thresholds first, and set clear rules for how quickly frontier AI developers should notify their own governments and what they must disclose. Revisit these guidelines as AI capabilities grow.
  2. Run parallel tracks on loss of control and misuse. Both sides have signaled willingness to work on each. But uncontrollable agents, as well as non-state cyber and bio threats, raise different reporting questions, and separating them prevents one from derailing the other.
  3. Keep the dialogue off the bargaining table. Frontier AI risk is too consequential to be tied to the vagaries of the broader relationship. The dialogue and its official working groups should meet on schedule, especially when relations fray.
  4. Accelerate the official track with outside expert support. Bilateral working groups of engineers, researchers, and national security practitioners should probe each side’s positions and deliver draft definitions, reporting thresholds, and stress-tested scenarios to the dialogue on a set timeline.

Why a “crisis” hotline isn’t enough

Washington and Beijing are not short on hotlines; they have a variety of military direct lines, including in the space and cyber domains. What they lack is a track record of answering when it counts. After a U.S. Navy surveillance plane collided with a Chinese fighter jet in 2001, U.S. officials spent days trying to reach Chinese leaders. China also declined Pentagon calls after the 2023 balloon shootdown. Part of the problem is structural. In Beijing’s system, answering a crisis call is a political decision, and picking up can look like rewarding the other side. Importantly, crisis lines only work when using them is already routine. The U.S.-Soviet link earned that habit in the 1967 Six-Day War, the 1971 Indo-Pakistani War, and the 1973 Yom Kippur War. The U.S.-China relationship never has. A routine reporting channel builds that habit before a crisis demands it.

Some of the hardest design questions involve labs, not governments. No one has settled either the method or speed at which a frontier developer should report an incident to its own government, let alone how that report reaches the other side. Who sees an incident first also depends on the model. Labs can often spot both loss of control indications and misuse on systems they host. However for open-source models, no lab sees how they are used and detection falls to intelligence and law enforcement, if it happens at all. Absent shared thresholds, labs lack clarity on what to report, and governments never see what does not get escalated. There is an asymmetry to account for as well. U.S. labs are private companies reporting to a government, while Chinese labs operate in closer proximity to the state. In addition, many of China’s leading models are open-weight. A shared framework has to work for both.

Two different risks, one aligned approach

Both capitals have conveniently aligned on the threats requiring collective focus. Bessent listed uncontrollable agents alongside non-state cyber and bio threats, and Xi’s July keynote at the World AI Conference in Shanghai paired preventing malicious use with keeping AI under human control. Uncontrollable agents are a loss of control problem: a system behaves in ways its operators did not intend, and the first to know is usually the frontier AI lab that built or deployed the agents. Cyber and biological threats from non-state actors, on the other hand, are a misuse problem. Here the system works as designed, but in the wrong hands it gives a hacker or would-be bioterrorist capabilities they could not otherwise build.

Each calls for different reporting protocols. For loss of control, the questions are how fast a lab flags anomalous behavior and how much technical detail crosses borders. For misuse, the questions are what counts as meaningful uplift, and how two rivals share threat information about third parties without exposing sources. The case for separate tracks is practical. Misuse reporting will quickly run into disputes over which hackers are truly non-state, and loss-of-control reporting will test how much labs are willing to disclose. Neither problem should hold the other hostage.

Beijing is more willing than the headlines suggest

Bessent has said China has surely had AI incidents but won’t disclose them, and Xinhua’s readout of the New York talks did not mention the incident line. Our experience suggests more nuance and room for engagement than that.

In our own Track II engagements with Chinese counterparts, we have found consistent willingness to work on AI crisis management, including incident reporting, communication channels, and shared definitions. Interest was especially strong in IST’s framework for monitoring AI loss of control, which adapts the intelligence community’s indications and warning methodology to flag behaviors like deception and self-preservation, and to grade incident patterns on a tiered severity schema. Frameworks like this are what an incident line needs, since they offer a shared answer to what should be reported, and how urgently. Whether China’s openness carries over into official channels remains uncertain.

Doing the groundwork

Unofficial Track II dialogues have earned their skeptics, as too many produce statements and reports that are difficult to act upon. The official Track I dialogue merits a different kind of support: disciplined, fast-moving working groups where both sides can test-drive ideas and rapidly iterate toward consensus. The right mix includes engineers and researchers from frontier labs and universities, think tank analysts, and former national security officials who know how governments decide. Industry belongs at the table because labs see incidents first, but it should not set the agenda. The groups should be responsive to Track I priorities and hand governments vetted options rather than opinions, without committing either side in advance.

Congress appears to be moving in the same direction. A bipartisan bill from Reps. Sam Liccardo and Kevin Kiley would clear potential legal barriers so that U.S. experts at frontier labs, universities, and think tanks can engage directly with Chinese counterparts.

Built to outlast politics

U.S.-China risk reduction channels have a habit of going dark exactly when they are needed most. Dialogue has too often been treated as a reward to grant or withhold. After Speaker Pelosi’s 2022 visit to Taiwan, Beijing suspended military talks and climate cooperation in a single stroke. The AI dialogue is especially exposed to shifting geopolitical dynamics. It was born in the trade track and negotiated alongside a tariff truce, so it could easily become one more concession to trade or withhold.

That would be a mistake for both sides. AI risk does not take a break when relations sour. A model that escapes its operators’ control, or arms a non-state actor, is every bit as dangerous in the middle of a trade dispute. Either the world’s two leading AI powers manage these risks together, or no one does. Without a bilateral reporting channel, Washington would lose the prospect of visibility into incidents within a system that does not currently disclose them. Beijing would give up early warning from the U.S. labs operating at the frontier, plus credibility for its own push to lead on global AI governance.

Bessent’s announcement is a welcome first step. The Shenzhen meeting will show whether the dialogue becomes an institution or a talking point. Washington and Beijing should use it to set a working agenda on loss of control and misuse, scope the incident line against that agenda, and bring in the unofficial channels that can help. A successful dialogue will produce an incident line that gets used on an ordinary Tuesday, so that someone picks up on the day it matters.

Topics

Share

Facebook
Twitter
LinkedIn
Print

Related Content

MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST