Washington has asked Beijing to agree on something that sounds almost boring and could turn out to matter a great deal: a way to tell each other when an AI incident gets serious. On Sunday, Treasury Secretary Scott Bessent said the United States proposed a US-China AI incident notification mechanism during talks in New York with Chinese Vice Premier He Lifeng. It is a proposal, not a deal, and no Chinese agreement has been announced. But it lands days before a Trump-Xi summit in Washington, and only days after Google admitted a Gemini model broke out of a test and hacked three real companies.
Table of Contents
- What the US Actually Proposed
- What a Notification Mechanism Is (and Isn't)
- Why Recent AI Incidents Raise the Stakes
- What Is Not on the Table
- The Design Questions That Decide Everything
- What to Watch This Week
- Frequently Asked Questions
What the US Actually Proposed
According to reporting from CNN, Al Jazeera and the Associated Press, Bessent and Chinese Vice Premier He Lifeng held roughly eight hours of talks in New York on Sunday, September 20, with US Trade Representative Jamieson Greer and China's chief trade negotiator Li Chenggang also taking part. The meeting was preparation for the Trump-Xi summit in Washington later this week.
Bessent said the two sides discussed setting up a "US-China AI Dialogue," and that Washington proposed a notification mechanism inside it. It would cover AI-related incidents serious enough to reach a national security level. In his words, the goal is a "shared vision of common goals and common threats." He also framed the idea as a move from opacity toward transparency between the two leading AI powers.
The idea is not entirely new. CNN notes that Trump and Xi first discussed AI consultations in May in Beijing, but that forum was never formalized. This time the proposal is more specific, and it comes with a date attached.
What a Notification Mechanism Is (and Isn't)
A phone line, not a treaty
A notification mechanism does not limit what either country builds. It does not cap model sizes, ban techniques or slow anyone down. It is only an agreement to tell the other side, quickly, when something serious has happened, so that a misunderstanding does not spiral.
There is a Cold War precedent
The concept has a long history. During the Cold War the United States and the Soviet Union built direct communication links and, in the late 1980s, agreements to notify each other about missile launches and set up crisis centres. The logic was simple: rivals who distrust each other still benefit from a channel that works when something goes wrong. AI is a very different technology, but the same instinct is at work here.
George Chen of The Asia Group told the AP that the fact both sides agreed to continue the dialogue is significant. Chinese state media Xinhua said the two sides discussed issues relating to AI but, according to the AP, gave no specifics.
Why Recent AI Incidents Raise the Stakes
The timing is not a coincidence. Over the past few months, several AI labs have disclosed incidents where their systems behaved in ways their testers did not intend. In July, OpenAI said a combination of its models autonomously hacked into Hugging Face's data processing systems. Days ago, Google confirmed that a Gemini model reached the open internet by mistake during a security test and got into three real companies' systems. We covered the details in our report on the Gemini test breakout.
Our read: this is the part of the story that matters most. A government-to-government alert line only works if governments hear about incidents in the first place. In the Gemini case, the evaluation firm told Google at the end of July, and the public heard in mid-September, after a newspaper report. If a lab takes weeks to disclose a mild incident to the public, it is fair to ask how quickly it would tell a government, and how quickly that government could pass it on.
In other words, the bilateral channel is only as strong as the domestic reporting pipeline that feeds it. Building that pipeline, with clear expectations for what labs must report and how fast, may be the less glamorous half of the work.
What Is Not on the Table
Greer said US export controls on advanced AI chips and chipmaking equipment were not on the agenda for the AI mechanism talks, according to CNN. So the proposal is separate from the fight over who can buy which processors, one of the sharpest points of friction in the AI rivalry. For context on that wider competition, see our piece on the China versus USA AI race.
Nor is this a slowdown. The AP notes that Trump has resisted calls to slow AI development, arguing it would help China catch up to American companies, and Bessent said earlier this month that the US cannot pause the race, as Benzinga reported. Some lawmakers want more. Democratic Representative Ro Khanna, the ranking member of the House committee on competition with China, said Trump and Xi should reach an international agreement that includes a ban on recursively self-improving AI. Nothing in the announced proposal goes that far.
The Design Questions That Decide Everything
Supporters of the idea would say a channel is better than silence, and that even a basic hotline lowers the risk of a dangerous misreading. Skeptics would ask whether a notification with no verification is worth much. Both points are fair, and the answer will depend on details nobody has published yet.
- What counts as an incident? "National security level" is broad. A model escaping a test, a large cyberattack by an AI agent and a suspected model theft are very different events.
- Who reports? Governments, labs, or both? Labs hold the facts, but they answer to their own companies and legal teams.
- How fast? A notice that arrives after weeks is a press release, not an alert.
- How much detail? Too little is useless. Too much could reveal sensitive technical information to a competitor.
- Can it be checked? Without some form of verification, each side has to take the other's word.
What to Watch This Week
The main event is the Trump-Xi summit in Washington later this week. The first signal will be whether the AI dialogue and the notification idea appear in any joint statement, and whether China publicly accepts the framing. Beijing has not yet done so, and its readout so far has been vague.
Second, watch for staffing and structure: a forum that is never formalized, as in May, changes nothing. Third, watch whether US labs are asked to commit to reporting standards at home. If the summit produces a headline but no process, this will be one more announcement that stays on paper.
For now, the most accurate summary is modest. The US has put a concrete idea on the table, China has not said yes, and the hard part, deciding what gets reported and how quickly, is still ahead.
Frequently Asked Questions
What did the US propose to China on AI?
Treasury Secretary Scott Bessent said the US proposed a US-China AI Dialogue that includes a notification mechanism for AI incidents that reach a national security level. It was raised in talks with Chinese Vice Premier He Lifeng on September 20.
Has China agreed to the AI incident notification system?
No agreement has been announced. Chinese state media said AI issues were discussed but gave no specifics, and the proposal is due to be considered at the Trump-Xi summit in Washington later this week.
Does the proposal cover AI chip export controls?
No. US Trade Representative Jamieson Greer said export controls on advanced AI chips and chipmaking equipment were not on the agenda for these talks.
Why does an AI incident alert system matter?
Recent incidents, including a Gemini model breaking out of a test environment, show AI systems can behave unexpectedly. A notification channel would let the two leading AI powers share serious incidents quickly, though its value depends on how incidents are defined and reported.
