The United States and China opened AI safety talks this week, with Treasury Secretary Scott Bessent announcing that both sides had discussed setting up a notification mechanism to flag when AI systems pose threats or behave unpredictably. The disclosure came ahead of meetings between Donald Trump and Xi Jinping scheduled for Thursday and Friday, with a follow-on session already booked for November. Analysts who reviewed the proposal say it is thinner than it sounds.
People familiar with Bessent's plan said the channel would run through existing diplomatic infrastructure and include no officials with technical expertise to assess the urgency of risks described in any alert. One source described the arrangement using what they called "the scientific, technical term: BS." China has not publicly acknowledged the proposal.
The timing is awkward. Two weeks ago, Trump's Justice Department accused six of China's leading AI makers of stealing from US frontier labs — a charge China strongly disputes. Trump has continued to expand export controls aimed at blocking Chinese access to advanced chips, and Congress is weighing bills that would tighten hardware restrictions further. On Truth Social, Trump wrote: "WHOEVER WINS AI, WINS! We are leading China, and all others, and will continue to do so."
Key facts
- 01Treasury Secretary Scott Bessent said the US and China have discussed a new AI safety notification mechanism ahead of Trump-Xi meetings Thursday and Friday.
- 02The proposed channel involves no officials with technical expertise, with one source familiar with the plan calling it 'BS.'
- 03Two weeks ago, the Justice Department accused six of China's leading AI makers of stealing from US frontier labs.
- 04Stanford's Alvin Wang Graylin predicts some Chinese open models may soon exceed 80 percent global market share.
- 05A follow-on US-China meeting is already scheduled for November.
Sam Bresnick, a research fellow at Georgetown University's Center for Security and Emerging Technology, told Ars Technica that routing safety communications through an existing diplomatic line is preferable to standing up a new one, but that the absence of technical staff caps what the mechanism can accomplish.
“It's an existing channel, which I think is better than creating a whole new channel.”— Sam Bresnick, Research fellow, Center for Security and Emerging Technology, Georgetown University
Bresnick said the channel is "better than nothing" but that he has little confidence it will make a major difference. Without engineers or model-evaluation specialists on either end, the two governments cannot have granular conversations about how they measure risk, particularly military risk — the category where a shared vocabulary matters most.
Su Lian Jye, chief analyst at research firm Omdia, told the South China Morning Post that the notification system could promote transparency but would not resolve the underlying disputes over model distillation, pricing competition, or the pace of frontier development.
“I don't think the dialog will remove all concerns and differences on distillation, pricing competition, and pacing.”— Su Lian Jye, Chief analyst, Omdia
Su added that turning the proposal into a working tool would require both countries to agree on risk classifications, notification triggers, response protocols, and regular review procedures — none of which is in place. Representative Ro Khanna, ranking Democrat on the House Select Committee on Strategic Competition with the Chinese Communist Party, argued on CBS's "Face the Nation" that the talks should go further, pushing for an international agreement banning recursive self-improving AI and adding safeguards against AI-enabled biological or nuclear weapons.
Alvin Wang Graylin, a digital fellow at Stanford Digital Economy Lab who has advised governments on AI governance and helped shape recommendations for exactly this kind of notification system, called the development positive. He noted that the November follow-on meeting suggests both sides see value in continuing. Graylin argued the two countries share more risk than they acknowledge, from bad actors weaponizing AI against critical infrastructure to gaps in model auditing practice. China regularly audits AI models and could share findings from hundreds of reviews; the US has more experience auditing frontier systems specifically.
Graylin has been sharply critical of the framing that dominates Washington's AI discourse. In a September article for the Quincy Institute, he called the "AI race" narrative deeply flawed, arguing there are actually two races — one for raw intelligence and one for market dominance — and that the US is winning revenue while losing global users. Adoption of Chinese open models has exploded in the last six months, and Graylin predicts some may soon exceed 80 percent market share as CEOs cutting IT budgets reach for cheaper alternatives that keep customer data in-house.
“US-China capability gaps at the frontiers of AI technology typically last only a few months, and there is no competitive 'moat' that will secure a permanent advantage to either nation.”— Alvin Wang Graylin, Digital fellow, Stanford Digital Economy Lab
Graylin argued that even winning the frontier race would not deliver the durable advantage that Trump and executives including Sam Altman describe. Frontier gaps last months, not years. And US safety testing itself extends the window competitors have to catch up: deploying an untested superintelligent system to preserve a lead would create larger risks than the gap it closed.
Bresnick offered a structural reason China may treat the channel with suspicion. Inside China, he said, there is not the same public fear of uncontrollable AI, partly because the state believes it can control the technology. That could shift over the next six months to a year as Chinese labs approach frontier capability. Until then, when US officials and CEOs pitch American-led global AI standards, Beijing is likely to read the safety agenda as a code word for suppressing Chinese AI.
The Bessent channel is a low-cost gesture that lets both governments claim engagement without conceding anything substantive. That is not nothing — a bad line of communication is still a line — but it is worth naming for what it is. The real test is whether the November meeting produces the classifications, triggers, and protocols Su described, or whether the mechanism becomes another venue for the two governments to talk past each other while the actual competitive dynamics — open-model adoption, chip access, and the pace of deployment — play out on their own timelines.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.



