US And China Agree AI Safety Talks And A New AI “Incident Line”
US And China Agree New AI Safety Talks As Rival Superpowers Confront Shared Risks
Washington And Beijing Open A New Channel For The World’s Most Dangerous AI Incidents
The United States and China have agreed to establish a formal dialogue on artificial intelligence that includes an “incident line” for communicating during serious AI safety incidents, according to US Treasury Secretary Scott Bessent.
Bessent said on Monday, September 21, that senior American and Chinese officials would meet again in roughly two months in Shenzhen, China, to continue discussions about artificial intelligence dangers and the communication protocols that should apply when something goes seriously wrong.
The development is significant because Washington and Beijing remain intense competitors in artificial intelligence, advanced computing and semiconductor technology. Yet the latest talks suggest that both governments are exploring whether some AI risks are serious enough to require communication even while that technological rivalry continues.
It is important, however, not to overstate what has been created.
This is not yet evidence of a Cold War-style emergency telephone sitting permanently between the White House and Beijing. The language being used publicly is an “incident line” or “notification mechanism” — essentially a channel through which the two governments could communicate about sufficiently serious AI-related events.
The details of exactly what would qualify, who would make contact, what information would have to be disclosed and how quickly either side would be expected to respond remain to be developed.
What The US And China Have Actually Agreed
The latest announcement follows talks in New York between Bessent and Chinese Vice Premier He Lifeng.
Bessent told CNBC that the two sides had agreed to establish a formalised dialogue on artificial intelligence, including an incident line for communication about AI safety emergencies. A further round of discussions is planned in Shenzhen in approximately two months.
The next stage will involve trying to identify what dangers the two countries regard as sufficiently serious to justify joint protocols.
Bessent specifically referred to potential dangers involving uncontrollable AI agents and cyber threats involving non-state actors.
That distinction matters.
The initiative is not currently being presented as a broad agreement governing how American and Chinese AI companies build their models. Nor has either country agreed to slow its AI development programme.
Instead, the emerging framework appears to focus more narrowly on communication when AI-related events create potential national security consequences.
What Would An AI “Incident Line” Actually Do?
The most straightforward comparison is with crisis-communication mechanisms used between governments in other areas of national security.
Imagine, for example, that an autonomous AI system begins carrying out cyber operations against critical infrastructure.
Investigators might initially be unable to determine whether the activity was:
ordered by a government,
launched by a criminal organisation,
initiated by another non-state actor,
generated unexpectedly by an autonomous system,
or deliberately made to look as though another country was responsible.
That uncertainty could become dangerous extremely quickly.
A communication mechanism would potentially allow American and Chinese officials to contact each other, exchange limited information and attempt to establish whether an incident represented deliberate state action or something else.
Associated Press reporting ahead of the talks identified possible shared concerns including AI-enabled cyberattacks, biological misuse, serious model failures and a potential loss of human control over advanced systems.
Exactly which scenarios ultimately fall within the US-China mechanism has not yet been publicly defined.
Why Washington Wants More Transparency
Bessent has repeatedly presented transparency as one of the central goals.
After the New York discussions, he argued that the two countries need a shared understanding of both common goals and common threats.
He described the United States and China as the leading AI powers and said greater transparency between them was important.
The logic is similar to crisis-management arrangements developed in other strategically dangerous fields.
Artificial intelligence creates a particular problem because an incident can unfold at extraordinary speed.
A conventional diplomatic dispute may take days or weeks to escalate.
A cyberattack driven by automated software could potentially spread through computer networks almost immediately.
An advanced AI agent might also carry out thousands of actions before human operators fully understand what has happened.
That makes communication particularly important if one country initially believes the other has intentionally attacked it.
Rogue AI Agents Are Becoming Part Of The Discussion
Perhaps the most striking element of Bessent's comments was his explicit reference to uncontrollable agents.
AI agents differ from traditional chatbots because they can be given goals and permitted to perform sequences of actions — potentially using tools, accessing computer systems, writing code, communicating with other services or making decisions without constant human approval.
The more autonomy an agent receives, the more consequential unexpected behaviour can become.
Bessent said future US-China talks should address whether uncontrollable agents should be regarded as one of the leading common AI dangers.
That does not mean Washington is claiming that a catastrophic autonomous AI incident is inevitable.
It does show, however, that scenarios involving autonomous systems have moved beyond theoretical debates inside technology laboratories and are becoming part of government-level international security discussions.
Cybersecurity Could Be One Of The Biggest Areas Of Common Interest
Cybersecurity may provide the clearest reason for the two rivals to maintain an AI communication channel.
Advanced AI systems can already assist with software development, vulnerability analysis and other technically sophisticated tasks.
The same capabilities create concern about malicious use.
AP reported that experts see possible areas of shared concern including attacks against critical infrastructure. Chinese AI governance discussions have identified sectors such as electricity, telecommunications, finance and transportation as potentially vulnerable to frontier-AI risks.
A sufficiently serious cyber incident could therefore create risks for both countries regardless of where the underlying AI technology originated.
The difficult question would be attribution.
If malicious software generated or controlled by AI attacked an American electricity network, for example, determining who was ultimately responsible could become extraordinarily important.
An attacker might deliberately hide its identity.
It might route an attack through infrastructure in another country.
It could even attempt to manufacture evidence suggesting that a rival government was responsible.
An incident line would not solve those problems.
But it could provide another way to prevent uncertainty from immediately escalating into a larger geopolitical crisis.
The Agreement Does Not End The US-China AI Race
Any suggestion that Washington and Beijing are suddenly becoming technology partners would be misleading.
They remain strategic competitors.
The United States continues to restrict China's access to some advanced semiconductor technologies, while Beijing has accused Washington of attempting to constrain Chinese technological development.
Those export controls were not part of the proposed AI incident mechanism discussed during the latest negotiations, according to US Trade Representative Jamieson Greer.
Competition between American and Chinese AI companies also continues.
Chinese models including those developed by DeepSeek and Moonshot AI have increasingly challenged leading American systems on some benchmarks and capabilities, while US companies including OpenAI and Anthropic remain major participants in frontier-model development.
The safety talks therefore sit alongside — rather than replace — the wider contest for technological advantage.
There Are Still Major Disagreements
AI cooperation between the two governments faces substantial political and technical obstacles.
Washington has raised concerns about Chinese access to American AI technology and advanced chips.
Chinese officials, meanwhile, have criticised US restrictions on China's technology industry and rejected some American claims surrounding Chinese AI development.
AP reported that American allegations involving the extraction or “distillation” of capabilities from US models have become another area of disagreement, while Chinese officials have expressed their own concerns about advanced American AI systems.
That creates an unusual dynamic.
The two governments may simultaneously regard each other's AI programmes as strategic threats while also believing that uncontrolled AI behaviour could create risks neither side wants.
Those positions are not necessarily contradictory.
Nuclear powers, for example, have historically competed intensely while still maintaining crisis communications designed to reduce the possibility of accidental escalation.
AI could eventually create a comparable need for confidence-building measures, although the technologies and risks are very different.
China Has Been Less Specific Publicly About The Mechanism
There is also an important difference in how the development has been described publicly.
US officials have provided considerable detail about the proposed notification mechanism and the incident line.
Chinese state media has confirmed that He and Bessent discussed issues relating to artificial intelligence and described the broader economic and trade discussions as candid, in-depth and constructive, but the Chinese account cited by AP did not provide the same level of detail about the proposed mechanism.
That does not contradict Bessent's later announcement that the dialogue had been agreed.
But it means much of the publicly available detail about how the framework is intended to work currently comes from the American side.
The next negotiations in Shenzhen could provide a clearer indication of how Beijing views its scope.
Why Shenzhen Matters
Shenzhen is one of China's most important technology centres.
Holding the next round of discussions there would put negotiations inside a city closely associated with China's technology, electronics and advanced manufacturing industries.
According to Bessent, senior officials are expected to reconvene in approximately two months.
Those talks could begin answering some of the questions that remain unresolved.
What constitutes an AI safety incident?
How serious must it become before the line is activated?
Would cyber incidents automatically qualify?
Would an AI company's loss of control over an autonomous agent qualify?
Could governments communicate about biological or chemical misuse assisted by AI?
Would private AI laboratories have obligations to report incidents to their governments?
And perhaps most importantly: how much sensitive information would either side actually be willing to share?
AI Companies Could Face More Questions About Responsibility
Bessent has also connected international AI safety discussions to the responsibilities of AI developers themselves.
He argued that AI laboratories should be accountable for technologies they create and suggested companies must retain the ability to slow development where necessary.
That introduces another dimension to the debate.
A government-to-government incident line only becomes useful if officials know an incident has happened.
That means companies operating powerful AI systems may eventually need clearly defined procedures for notifying governments when something sufficiently serious occurs.
A future framework could therefore involve several layers:
AI laboratories identifying dangerous incidents.
National authorities evaluating their seriousness.
Governments determining whether an international notification is necessary.
Officials communicating through an agreed crisis mechanism.
None of that detailed architecture has yet been announced.
But creating the dialogue establishes a place where those questions can now be negotiated.
The Trump-Xi Summit Adds Another Layer
The AI agreement comes ahead of expected talks between US President Donald Trump and Chinese President Xi Jinping.
AI has become increasingly prominent in the wider relationship between the two countries.
Trump has repeatedly emphasised the importance of maintaining American technological leadership and has resisted arguments that the United States should broadly slow advanced AI development because of safety concerns. AP reported that his position has been that slowing American development could allow China to close the gap.
That makes the emerging dialogue notable.
The United States is not proposing that both countries stop competing.
Instead, the approach appears to be attempting to separate two questions.
Who leads the AI race?
And:
What happens if an AI incident becomes dangerous enough that neither side benefits from misunderstanding it?
Those are very different problems.
Washington and Beijing may remain unable to agree on the first while still finding reasons to cooperate on the second.
Could This Become The AI Equivalent Of A Crisis Hotline?
Possibly — but it is too early to describe it as a fully developed AI hotline in the traditional sense.
The term “incident line” suggests something more specific than ordinary diplomatic contact, but the operational details have not yet been published.
There is no publicly disclosed threshold for activation.
There is no publicly announced response timetable.
There is no indication yet of precisely which agencies would operate the channel.
And there is no evidence so far that either government has committed to disclosing highly sensitive information about its most advanced AI systems.
Those issues could determine whether the mechanism becomes genuinely important or remains primarily a diplomatic confidence-building measure.
Why The Agreement Could Matter Beyond America And China
If the mechanism develops into a functioning incident-notification framework, other countries could eventually study it as a possible model.
George Chen of The Asia Group told AP that the initial AI risk notification mechanism could establish a precedent for other countries.
That possibility matters because many of the most serious theoretical AI risks are international.
Malware does not necessarily remain inside national borders.
AI-generated biological information can move electronically.
Open-source models can be downloaded around the world.
Autonomous systems can interact with global digital infrastructure.
And an incident involving one powerful system could affect users, companies or governments in multiple countries.
International AI governance may therefore eventually need both broad institutions and narrower crisis-communication channels.
The US-China initiative could become one early experiment in the latter.
What Happens Next
The immediate milestone is the planned meeting in Shenzhen in around two months.
Officials are expected to continue discussing both the dangers that should fall within the framework and the communications protocols that would govern an incident.
The significance of the initiative will ultimately depend less on the existence of an “incident line” than on what the two governments agree to do with it.
A communication channel that is never used, activated too slowly or trusted by neither side would provide limited protection.
A mechanism with clear thresholds, rapid communication and enough technical information to prevent misinterpretation could be considerably more important.
For now, the development marks a rare area where the two countries at the centre of the global AI race have identified at least some potential shared interests.
America and China are still competing to build increasingly capable artificial intelligence.
They are now also beginning to discuss what they should do if those systems create a crisis neither side intended.

