The United States and China have spent much of the past several years treating artificial intelligence as an object of technological competition. Export controls, semiconductor access, model capabilities, investment restrictions, supply chains, and national computing capacity have dominated the relationship. A proposal discussed in New York on September 20 introduces a different institutional logic: communication about AI incidents that could rise to the level of national-security threats.
U.S. Treasury Secretary Scott Bessent said after talks with Chinese Vice Premier He Lifeng that the United States had proposed a notification mechanism and a continuing U.S.-China AI dialogue. The proposal remained preliminary ahead of the September 24 Trump-Xi summit. Its importance lies less in its immediate legal force than in the category it creates. AI is being treated simultaneously as a competitive technology and as a source of shared strategic risk requiring communication between rival states.
Competition creates a need for communication
Strategic rivals often develop channels precisely because rivalry creates opportunities for misinterpretation. Nuclear hotlines, military deconfliction procedures, advance notification arrangements, and incident-at-sea agreements have historically sought to prevent local events from becoming larger crises. AI introduces a different technical environment, yet several underlying problems are familiar: uncertain attribution, compressed decision time, incomplete information, dual-use systems, and the possibility that an incident in one state's infrastructure could be interpreted as deliberate action by another.
The proposed notification mechanism appears narrower than an arms-control agreement. Public reporting does not establish agreed thresholds, verification procedures, enforcement rules, or prohibited capabilities. It indicates that officials on both sides recognize a class of events for which opacity may impose unacceptable costs. That is already a meaningful institutional development.
What would count as an AI incident?
The design challenge begins with definition. An AI system might generate a national-security incident through cyber activity, autonomous targeting, misinformation affecting crisis decision-making, interference with critical infrastructure, or unexpected behavior in a system connected to military or financial networks. Some events could originate from governments. Others could arise from private firms, criminal groups, or systems operating beyond the direct intent of their deployers.
A useful notification mechanism would therefore require more than a telephone number. Officials would need categories of reportable events, contact points with authority to exchange information, procedures for distinguishing preliminary observations from verified findings, and safeguards against disclosure of sensitive technical details. The system would also need to operate during moments of political distrust, which is precisely when incentives to conceal information or interpret it strategically become strongest.
AI strategic stability differs from nuclear stability
The nuclear analogy has limits. Frontier AI is developed largely by private firms, diffuses through commercial infrastructure, and can be repurposed across civilian and military domains. Capability is difficult to measure through a small number of visible physical assets. Models can change quickly through software updates, tool access, fine-tuning, and integration with external systems. An incident-notification regime must therefore connect state diplomacy to corporate reporting and technical investigation.
This institutional heterogeneity could make AI crisis management unusually difficult. A government may need to notify another state about an event before it possesses a complete explanation from the company that built the model. A private provider may discover a cross-border security incident before national authorities do. Responsibility for classification, attribution, and disclosure can therefore become distributed across laboratories, cloud providers, cybersecurity agencies, military commands, regulators, and diplomatic institutions.
Rivalry and restraint can coexist
The notification proposal does not signal an end to technological competition. Export controls, industrial policy, semiconductor restrictions, model development, and strategic distrust remain central features of U.S.-China relations. The more interesting possibility is that competition itself is producing bounded forms of cooperation. States can seek technological advantage while sharing an interest in preventing accidental escalation or uncontrolled cross-border consequences.
This is how a strategic-stability regime often begins: through a limited problem that both sides prefer to manage despite wider disagreement. The decisive evidence will come from institutionalization. A recurring dialogue, agreed incident categories, designated authorities, exercises, and actual use during a crisis would indicate that AI risk management is becoming part of bilateral security architecture. A statement of intent without operational procedures would remain diplomatic signaling.
The governance question
The United States and China are entering a period in which AI policy cannot be understood through technological sovereignty alone. Competitive capability and shared vulnerability are developing together. Export controls seek to shape who can build advanced systems. Notification mechanisms seek to shape what happens when those systems behave in ways that affect both sides. The coexistence of these projects suggests that AI geopolitics is acquiring a second institutional layer: rules for managing the consequences of the competition itself.