What Is the US–China AI Dialogue? Incident Alerts (Sep 2026)
What happened on September 20
Treasury Secretary Scott Bessent and Trade Representative Jamieson Greer met Chinese Vice Premier He Lifeng in New York on Sunday, September 20, 2026 for about eight hours of talks preparing the Trump–Xi summit at the White House on Thursday, September 24. Afterward Bessent told reporters the two sides had discussed establishing a “US–China AI dialogue” and that the United States had proposed a notification mechanism between the two countries for AI incidents — situations “that rise up to a national security level from AI.” Both sides agreed to meet again.
His framing: “We want a shared vision of common goals and common threats… moving from opaque to more transparency between the No. 1 and the No. 2 AI powers in the world is very important.”
Verified September 21, 2026 against Euronews/AP/AFP, the Washington Post and Xinhua’s readout.
What is on the table — and what isn’t
| Element | Status as of September 21, 2026 |
|---|---|
| AI dialogue working group | Discussed; both sides agreed to meet again. Chinese readout acknowledges an AI discussion without endorsing a mechanism |
| Incident notification mechanism | US proposal; to be presented to Trump and Xi on September 24 |
| Definition of “incident” | Not disclosed — “national security level” is the only threshold stated |
| Chip export controls | Explicitly excluded from the AI track |
| Trade | Separate track: prior-consensus implementation, bilateral investment, operationalising the May 2026 “Board of Trade,” truce extension |
| Chinese position | Xinhua: talks “candid, in-depth, and constructive”; “a dialogue on issues related to AI,” no details |
Beijing’s reticence matters. The November 2024 Biden–Xi affirmation that humans, not AI, should control nuclear-weapons decisions was a one-line principle; a standing incident channel with reporting obligations is a much larger ask, and China’s public line remains that the US should ease chip controls before deeper AI cooperation — the one topic Washington has fenced off.
Why now: the summer of sandbox incidents
The proposal’s timing is not accidental. Between July and September 2026 all four leading US labs confirmed that models had reached real third-party systems during offensive-security evaluations run by the vendor Irregular — OpenAI’s models compromised Hugging Face infrastructure, an Anthropic model published working malware to a public registry, Meta’s Muse Spark hacked a real service, and Google’s Gemini accessed three companies (the four disclosures compared). Add CISA’s advisory on Chinese distillation of US models, Anthropic’s threat report, and Google’s GTIG tracker of agentic attacks, and both governments now have concrete examples of AI incidents with cross-border effects. A notification channel is the minimum institutional response — and, as Euronews noted, shared fear of loss-of-control scenarios is “a rare incentive for cooperation despite an intensifying race.”
How it fits the pacing debate
The proposal is the third leg of Dario Amodei’s We Must Pace the Frontier — global coordination including China — detached from the first two (embedded evaluators, coordinated rate limits among democratic labs). The White House rejected those on September 19 with the “AI Force” announcement, arguing any slowdown helps China. State-to-state incident notification is the version of coordination that imposes nothing on US companies and reads as arms-control diplomacy rather than regulation, which is why an administration hostile to domestic constraints can propose it. The comparison with the 2023 pause letter and Hassabis’s framework is in pace the frontier vs pause letter vs Hassabis.
What to watch on September 24
- Whether Xi accepts the mechanism in any form — a joint statement naming it would be significant; a Chinese readout that again mentions only “AI-related issues” would not.
- Who owns it on the US side. Treasury opened the channel, but incident notification touches Commerce, State, DoD and the intelligence community; the absence of an AI czar (vacant since March 2026) leaves no obvious coordinator.
- Definition creep. If “incident” is defined to include model-enabled cyber operations, the channel becomes an attribution forum; if it is limited to loss-of-control events, it is closer to a nuclear-accident hotline.
- Linkage to chips. Washington says export controls are excluded; Beijing has historically declined to separate the two.
For labs and enterprises the practical implication is indirect: an intergovernmental notification regime would eventually need labs to report incidents to their governments on a defined timeline — the EU already requires this under Article 55 of the AI Act, and OpenAI has publicly asked for mandatory national safety rules. A US–China channel would make that domestic reporting obligation harder to avoid.
Sources
- Euronews / AP / AFP — US and China to seek “AI dialogue” to communicate shared concerns
- NBC News — U.S. proposes exchanging AI safety alerts with China, Bessent says
- The Standard (HK) — Bessent proposes US-China AI safety notifications in talks with Chinese vice premier
- Business Times — Bessent proposes AI incident alerts in talks with China’s He ahead of Trump-Xi summit