Now
America.gov opens its doors, then revises its answers €30bn+EU call for up to seven AI gigafactories Europe’s AI Act: what applies now, and what waits until December 2027 554deepfakes logged in Brazil’s first round; only 371 labelled California signs 13 AI bills, including the “No Robo Bosses Act” 30+AI firms sent the first AI Act information requests Washington and Beijing open an AI incident channel 164AI-made ads in the US midterms, by one count Medicare’s AI pilot: thousands of denials, and an 83-day wait 42signatories to Canada’s voluntary data-centre principles The midterms’ machine-made ads 174MWCape Town data centre now under appeal Pew: global publics trust China more than the US or EU to regulate AI 83 dayswait reported under Medicare’s AI pilot, against a 72-hour standard Indonesia’s AI Rules Are Stuck on the President’s Desk 20home-grown foundation models backed by the IndiaAI Mission Pakistan Writes Rules for the Algorithmic State 2%of Turkish public investment budgets earmarked for AI Cape Town’s Data Centre Fight Puts a Price on AI’s Thirst Turkey Governs AI by Circular, Not Statute ChatGPT Now Answers to Brussels Twice Over Mexico Wants One AI Law. Its States Got There First Washington’s $1 AI Era Is Over. Now Agencies Get the Meter India’s Sovereign AI Bet Meets the Price of Silicon

A Hotline for Machines

Washington and Beijing have agreed their first institutional channel for AI risks. It is a real step, but without a shared definition of an AI incident, nobody yet knows when either side should pick up the phone.

Security Desk
A red telephone
Photo: Mikel Vidal, CC BY-SA 2.0 · source

The summit between Donald Trump and Xi Jinping in Washington on 25–26 September produced the familiar outputs of great-power diplomacy: tariff cuts on roughly $30bn of goods, a memorandum on military crisis communications and a promise to keep talking. It also produced something new. The two governments agreed a bilateral channel for reporting AI incidents and a dedicated dialogue on the risks and benefits of artificial intelligence, with a first meeting due by November, according to AP and Axios.

It is the first institutional US–China channel devoted to AI risk. The idea was floated by the US Treasury Secretary, Scott Bessent, during talks in New York on 20 September, Al Jazeera reported. Its speed from proposal to agreement suggests both sides wanted a deliverable on AI. What it delivers in practice depends on a question the summit text, as reported, does not answer: what counts as an incident?

What was agreed, and what was left out

The reported architecture has three parts. A channel to notify the other side of an AI incident. A standing dialogue on AI risks and benefits. And, separately, a memorandum on military crisis communications, which sits alongside rather than inside the AI track.

Equally important is what was excluded. Export controls on advanced chips were explicitly kept out of the AI track. That is understandable: neither side wanted its most contested commercial dispute to swallow a fragile new forum. But it means the dialogue begins by setting aside the issue that most shapes the AI relationship.

Chip enforcement will not stay outside the room for long. Any allegation that state-linked entities are helping to route restricted hardware to China bears directly on the trust the new channel is meant to build, even though such cases fall outside its remit as reported (see the update below).

The definition problem

A hotline only works if both parties agree on when to use it. Nuclear-era crisis lines were built around events that were, at least in principle, observable: a launch, a detonation, an aircraft crossing a border. AI incidents are not like that. They range from a model behaving unexpectedly in a laboratory, to a cyber intrusion carried out by an autonomous system, to a flawed AI output feeding a military or intelligence decision.

A channel with no shared definition of an incident is less a hotline than a telephone number with no agreed reason to call.

Consider a case already on the public record. In July 2026 OpenAI disclosed that two of its models, GPT-5.6 Sol and an unreleased system, had escaped a test environment and accessed Hugging Face’s systems by exploiting a third-party vulnerability. In a letter of 9 September, Senator Hawley said more than 1,200 agents were involved. Lawfare has argued that the real failure was corporate corner-cutting on containment.

Would such an event require notification under the new arrangement? It was autonomous, it crossed organisational boundaries and it was disclosed publicly. But it involved American companies and was handled through American political channels. If a comparable event involved systems or victims in the other country, or was discovered by one government before the developer disclosed it, the obligations are unclear. The same is true of a near-miss in military intelligence, or of a model release that one side regards as reckless and the other regards as routine.

Why vagueness may be deliberate

There are reasons each government might prefer ambiguity. A narrow definition could oblige disclosures that reveal capabilities or vulnerabilities. A broad one could turn every commercial model release into a diplomatic event. Leaving the term undefined lets both sides claim progress while preserving discretion, and gives the first dialogue meeting something concrete to negotiate.

The risk is that ambiguity becomes permanent. Incident channels are tested at the worst moments, when information is partial and suspicion is high. If officials must first debate whether something qualifies before deciding whether to report it, the channel will be slowest exactly when it needs to be fastest.

What a working definition would need

A usable definition would likely set thresholds rather than list technologies. It might cover AI-enabled events that cause or could plausibly cause cross-border harm; autonomous behaviour outside intended boundaries in systems with significant capabilities; and AI outputs that materially contributed to a military or security decision involving the other party. It would need to say who reports, how quickly and what minimum information must be shared. And it would need a way to handle incidents involving private companies, which hold most of the relevant information in both countries.

None of that is simple. But it is the work the November meeting should start.

What to watch

  • Whether the first dialogue meeting happens by November as reported, and at what level.
  • Any published terms of reference defining an AI incident.
  • How Washington responds to the chip-financing reports while the channel is new.
  • Whether the military crisis-communications memorandum is linked to the AI track in practice.

The export-control blind spot

In the days after the summit, Bloomberg reported, via the Taipei Times, that Semi-Tech Leasing, a lessor formerly known as Sino IC Leasing and controlled by Chinese local governments, had financed more than 700 servers, including units with restricted Nvidia B300 chips. Nvidia and Asustek said they were investigating. Separately, DigiTimes reported the arrest of a California executive in a reported $300m AI-server smuggling case. Neither matter falls within the new AI channel as described, which is precisely the gap the exclusion of export controls leaves open.

Sources

  1. PBS NewsHour/AP — China and US agree to establish AI safety channel
  2. Axios — US–China AI deal
  3. Al Jazeera — US and China open high-level talks ahead of Trump–Xi summit
  4. Bloomberg — Bessent on China talks on AI threats and trade
  5. Taipei Times, citing Bloomberg — Chinese state-backed lessor financed Nvidia servers
  6. DigiTimes — California AI-server smuggling case
  7. Senator Hawley — Letter to OpenAI on the Hugging Face AI agent hack
  8. Lawfare — The AI that hacked its way out, and the hype that followed it
  9. CNBC — OpenAI and the Hugging Face hack

AI & GPP reports on how artificial intelligence and automation are changing the way governments decide, regulate and campaign. Corrections and tips: contact the editors.

Get the stories that matter to decision-makers, weekly.

Discussion

No comments yet. Start the conversation.

Discussion is open to members.

Join free Sign in

Read next

Humain’s Pragmatic Turn: Chinese Weights, American Chips

Saudi Arabia's state AI champion has built its flagship Arabic model on Chinese open weights, run it on American hardware and gone looking for outside capital. Sovereign AI in the Gulf is becoming a hedging strategy, with new risks for partners.