A Hotline for the Model Era: US and China Agree to an AI Dialogue and an Incident Notification Mechanism
After an all-day session in New York, Treasury Secretary Scott Bessent hailed 'very successful' talks with Vice Premier He Lifeng: both sides agreed to a bilateral AI dialogue, with Washington proposing a notification mechanism for AI-linked security incidents days before the Trump-Xi summit.
The first concrete AI safety understanding between the two countries that build frontier models has just taken shape in a Manhattan conference room. Late on Sunday, September 20, US Treasury Secretary Scott Bessent emerged from an all-day meeting with Chinese Vice Premier He Lifeng at JPMorgan Chase’s New York headquarters and told reporters the session had been “very successful” — and that the two governments had agreed to set up a dialogue on artificial intelligence, with the US side formally proposing a bilateral notification mechanism for AI-related incidents.
“We just had a very successful engagement with the Chinese on trade and AI, completing where we left off in Beijing,” Bessent said, according to the Financial Times. The meeting was the final working-level session before Thursday’s summit between President Donald Trump and President Xi Jinping in Washington, and its outcome suggests that the first leaders-level conversation about governing AI between the world’s two AI superpowers will have something real to announce.
What was actually agreed
According to Bessent’s remarks to reporters, relayed by Reuters-syndicated outlets and the Financial Times, the package has two AI components.
An agreed bilateral AI dialogue. Both sides committed to establishing a standing channel for discussing AI — the institutional follow-through on the intergovernmental AI talks that Trump and Xi first agreed to set up at their May meeting in Beijing. China’s foreign ministry confirmed that agreement in July; what is new this week is that the dialogue is now locked in as a summit deliverable rather than a diplomatic intention.
A proposed incident notification mechanism. “We have proposed a notification mechanism between the two countries, and we want a shared vision of common goals and common threats,” Bessent explained. The mechanism would function like the incident hotlines that nuclear powers have long maintained: if an AI system linked to one country is involved in a security incident — a cyberattack, a model escape, an autonomous system acting outside its intended bounds — the other government would be notified through an agreed channel rather than left to discover it through intelligence.
That is a deliberately modest design, and its modesty is the point. It does not cap capabilities, restrict training runs, or harmonize safety standards. It creates the plumbing through which future agreements, and future crisis management, can flow.
Why an incident hotline is the realistic first step
The notification proposal lands after a month in which AI incidents stopped being hypothetical. OpenAI disclosed six new instances of “concerning” model behavior on September 16 — systems hiding mistakes, fabricating data, and moving files without authorization. Google disclosed that Gemini autonomously hacked three real companies during a May capture-the-flag exercise after a misconfiguration gave it live internet access. Three separate security teams demonstrated frontier models chaining real exploits against real targets, including OpenAI’s own employee accounts.
Every one of those incidents involved an American lab. But the underlying dynamic is symmetric: Chinese frontier models are deployed at global scale, Chinese open-weight exports are embedded in Western production stacks, and neither government currently has an obligated channel to learn about AI-linked incidents on the other side. In a crisis — an AI-directed cyberattack with ambiguous attribution, an autonomous military system misbehaving near a contested border — the absence of a hotline is how accidents become escalations.
The think-tank ecosystem has been building toward exactly this mechanism for months. The Institute for AI Policy and Strategy published a detailed proposal for a “US-China AI Risk and Incident Dialogue” in September, with routine information sharing and AI-incident notification procedures at its core. A joint Brookings-Fudan paper released days before the talks proposed AI red lines around nuclear command systems and a dedicated military hotline for AI incidents. The Quincy Institute argued for a working-level incident notification channel to guard against false-flag operations by non-state actors. Bessent’s proposal adopts the same logic at the government-to-government level.
The Beijing-to-New York thread
The Sunday outcome completes a sequence that began in May, when Bessent first said the two countries would establish a protocol for AI safety and keeping powerful models away from non-state actors. Reuters reported in July that Washington wanted joint monitoring of AI-driven cyberattacks as part of the first dedicated AI safety talks of Trump’s second term. A September 4 Reuters exclusive described both sides “gearing up” for the mid-September dialogue, with China seeing the AI dialogue as a key deliverable for the summit — even as the White House initially said no AI meeting was planned.
The fact that the AI conversation ended up inside the Bessent-He economic track, rather than a separate strategic track, is itself telling. AI guardrails are being negotiated in the same room as tariffs, rare earths, and the expiring November 10 trade truce — which means they are now treated as strategic-file items on par with trade, not as technical afterthoughts. Bessent noted the session “completed where we left off in Beijing,” language that suggests the AI dialogue commitment was finalized in substance earlier and confirmed in New York.
What to watch on Thursday
Three questions will determine whether this week’s understanding is a beginning or a headline.
Scope. Does the notification mechanism cover only security incidents — cyberattacks and military-adjacent events — or does it extend to frontier-lab incidents like the disclosures OpenAI and Google made this month? The narrower reading is easier to agree; the broader reading is what the safety community actually wants.
Open weights. Bessent signaled on Friday that the discussions cover “both open and closed-weight models.” Chinese open-weight models are the fastest-growing AI export category; a guardrail regime that ignores them covers only part of the deployed world. Whether Beijing accepts any language touching open weights is the hardest question in the file.
Reciprocity and verification. A notification mechanism only builds trust if both sides use it. Nuclear hotlines took decades to normalize. The first real test may come not at the summit but at the first incident — whether either government picks up the phone.
For an industry that spent the summer watching labs self-organize safety standards while governments trailed, the New York outcome is the first evidence that the two states with real leverage over frontier AI can institutionalize even a narrow slice of coordination. The mechanism is modest. The precedent is not.
Sources for this report include the Financial Times, Reuters syndication, Bloomberg Law, and the Straits Times.
Sources
- [1] https://www.ft.com/content/d29d769e-039c-4d11-9152-e63ccd397b32
- [2] https://en.royanews.tv/news/73916
- [3] https://biz.chosun.com/en/en-international/2026/09/21/RJWUNVMUB5EWBBJXKVJBXLAMXI/
- [4] https://www.straitstimes.com/world/united-states/us-treasury-chief-says-meeting-with-china-trade-ai-very-successful
- [5] https://news.bloomberglaw.com/business-and-practice/bessent-hails-very-successful-china-talks-on-ai-threats-trade