What US-China AI safety could deliver even without a deal

What US-China AI safety could deliver even without a deal

On September 17, 2026, PBS NewsHour, citing Associated Press reporting, confirmed that artificial intelligence governance is on the agenda for a planned Washington meeting between President Donald Trump and Chinese leader Xi Jinping next week. Any serious plan for US-China AI safety will be judged less by a grand communique and more by whether both sides set up practical guardrails that work under tension.

That’s the right test. According to the PBS/AP report, American tech leaders argue that averting worst‑case “rogue AI” scenarios will require some degree of cooperation with China, even as both capitals race for an edge. Trump has warned that stronger regulation would help Beijing. The two frames collide. Yet they also define the small zone where progress is possible.

What’s on the table in Washington

The PBS/AP piece lays out a blunt read: both governments want decisive advantage in AI, and neither trusts the other’s motives. Still, experts see room to move. Samm Sacks of Johns Hopkins told PBS NewsHour that a formal accord may be out of reach, but that leaders can “create political space” by acknowledging shared risks and asking their systems to work the problem below the summit level.

“A formal agreement or consensus may be near impossible, but they do not need to go that far,” Sacks said. “Trump and Xi just need to create political space by acknowledging AI poses risks to both countries.”

There’s precedent for limited alignment. China signed the Bletchley Declaration at the United Kingdom’s AI Safety Summit in November 2023, which set a baseline that frontier AI can pose serious risks and merits shared inquiry. The declaration did not bind any state to specific controls, but it established a common starting point. That low‑bar consensus is a model for what Washington might try to extend now. The text is public on the UK government’s site, and it remains the most inclusive statement to date of cross‑border concern over advanced models (Bletchley Declaration).

There’s also a channel to use. The United States and China held their first government‑to‑government talks on AI in Geneva in May 2024. The U.S. State Department’s readout emphasized risk and safety. It didn’t promise outcomes, but it proved dialogue exists and can continue away from cameras (State Department readout).

At the same time, the structural friction is real. U.S. semiconductor export controls target advanced computing items that support AI development. The goal is to limit military end uses and mass surveillance. Those measures, described in the Federal Register in October 2023, complicate scientific exchange even when safety is on the agenda (Federal Register).

Why US-China AI safety matters beyond politics

Safety failures do not respect boundaries. Weights leak. Model exploits spread in hours. Open research papers and codebases travel faster than policy memos. If a model trained in one country can automate elements of cyber intrusion or lower the barrier to designing a biological threat, the exposure is global. That’s why a thin lane of cooperation makes sense even in a hard rivalry.

Standards bodies already point to a shared vocabulary for risk. The U.S. National Institute of Standards and Technology’s AI Risk Management Framework lays out functions—govern, map, measure, manage—that firms and agencies can match without trading secrets. That common language can anchor technical exchanges on evaluations and incident reporting (NIST AI RMF).

Put simply: if Washington and Beijing can agree on a few practical moves, the rest of the world gains time to align national rules, and developers get clearer targets for testing frontier systems. If they don’t, we drift toward incompatible safety regimes, more duplication, and higher tail risk.

Three near‑term steps both sides could take

The PBS/AP reporting suggests any initial agreement may be “superficial.” That’s fine if it buys signal and time. Here are three narrow steps US-China AI safety talks could deliver now without touching core competitiveness:

  • Stand up an emergency hotline for high‑risk AI incidents. The two governments could create 24/7 contacts to share time‑sensitive alerts about frontier model failures that present transnational harm. Think of a limited‑use channel modeled on cyber incident coordination: rapid notification, minimal data, and a bias for speed. No IP, no weights—just enough to cue mitigation on the other side.
  • Adopt a shared template for model evaluations and red‑teaming results. Using public frameworks like NIST’s, agencies could publish comparable summaries when they test or commission tests of dangerous capabilities—cyber intrusion support, chemical or biological design assistance, or long‑horizon autonomous actions. Each side keeps its methods; the value is a common taxonomy and the practice of publishing enough to support peer scrutiny.
  • Commit to parallel transparency on very large training runs. Without sharing model designs, each side could notify the other when a training job exceeds a pre‑set compute threshold and include basic safety plans: sandboxing, staged deployment, and red‑team scope. The threshold can map to what export rules already signal about system scale, keeping disclosures thin but meaningful.

None of these steps resolves who leads in AI. They do address the risk channel that most worries both sets of officials and executives. They are also cheap to start: a memo, a directory, and a template get you most of the way there.

How to read the meeting if no treaty appears

Because the PBS/AP story frames expectations for next week’s session, it helps to set a scoreboard in advance. Look for three signals. First, the leaders reference “working‑level” or “technical” contacts on safety with a plan to meet again on a date certain. Second, there’s a line about incident communication or a standing contact point. Third, readouts mention comparable evaluation practices or shared areas for testing, like biosecurity or cyber‑resilience. Any two suggest a live channel, not a photo op.

If none of those appear, allies will hedge. Europe, Japan, and others will keep building standards within their blocs. Companies will face diverging checklists. And the rest of the world will see safety as a zero‑sum extension of export policy. That pushes innovation and safety work into separate lanes, which helps no one.

It’s also worth watching how each side talks about regulation. Trump’s line, reported by PBS/AP, is that tighter rules could hand China an edge. Beijing, for its part, has used domestic rules to steer content and access even as it sponsors research. Both stances can coexist with a thin cooperation lane if leaders treat safety as shared plumbing, not strategy.

What cooperation would change on the ground

For developers, even a narrow agreement reduces uncertainty. If model evaluations line up across systems, labs can run one serious red‑team and satisfy multiple overseers. If there’s a hotline, incident response playbooks can add one call tree and meet expectations on both sides of the Pacific. For regulators, a template lowers drafting risk. It’s easier to copy success than invent alone.

Global initiatives can then scale. The Bletchley process showed that governments with different interests can still agree that some frontier model behavior is unacceptable. A live US-China AI safety channel would turn that from a one‑off summit into a working practice. It would also give both sides cover to keep the Geneva track open even when export controls—on chips, tools, or cloud access—tighten again.

The rivalry won’t pause. Export controls described in the Federal Register will still shape hardware access, and each side will still court partners and talent. But a thin, reliable lane for safety coordination is the rational minimum everyone can afford.

The next week’s meeting will test whether leaders can separate safety plumbing from power politics. If the readouts point to a hotline, a shared evaluation template, or parallel transparency on giant training runs, that’s movement. If they do it, the world gets a little safer while the contest continues. That’s what progress on US-China AI safety looks like in practice. For more on this, see nytimes.com.

Related reading: Hugging FaceFine-TuningOpen Source AI