US Proposes an AI Incident Alert System to China Ahead of the Trump-Xi Summit
Treasury Secretary Scott Bessent said the US proposed a notification mechanism with China for AI safety incidents that reach the national security level, during Sunday's talks with Vice Premier He Lifeng in Manhattan.
The United States has proposed a formal alert system with China for AI incidents that reach the national security level, Treasury Secretary Scott Bessent told reporters after Sunday’s talks with Chinese Vice Premier He Lifeng at JPMorgan Chase’s Manhattan headquarters, per Reuters and CNN. The two sides also discussed standing up a dedicated US-China AI dialogue with a national security emphasis, laid down as groundwork for an expected Trump-Xi summit. Bessent framed the proposal as mutual: “We want a shared vision of common goals and common threats.”
What the Mechanism Would Actually Do
The proposal, as Bessent described it, is a notification channel: when an AI-related event crosses into national security territory, on either side, the other government hears about it directly rather than through intelligence channels or the press. The closest existing analogues are aviation incident notification and nuclear-era crisis communication, and the logic is the same in all three cases: during an emergency, the cost of silence is misreading the other side’s response. An AI incident that hits national security level, a frontier lab compromise, an autonomous system malfunction with cross-border effects, a model-enabled attack on critical infrastructure, is exactly the kind of event where hours of ambiguity could escalate.
What makes this notable for practitioners is what it implies about how both governments now model AI risk. This is not a capabilities treaty or an export-control adjustment; it is an admission that incidents are expected, that they will cross borders, and that the two countries most likely to host them need a phone number to call.
Why Now
The timing maps onto the summit calendar, but the substance has been building. CNBC notes a prior Bessent-He meeting in South Korea tied to the leaders’ meeting, and AI has moved from the periphery of US-China trade talks to a core agenda item alongside tariffs and export controls. The context each side brings is asymmetric: US policy has centered on controlling frontier compute through export controls, while Chinese open-weight models have been taking over download charts on Hugging Face, which means Chinese-built models are deployed far outside Chinese jurisdiction. An incident involving an open-weights model fine-tuned by a third party would implicate neither government’s direct control, which is precisely the gap a notification channel is meant to paper over in a crisis.
Sunday’s venue and structure also signal continuity: working-level economic talks doubling as the vehicle for AI diplomacy, with the leaders’ summit as the deadline that forces specifics.
The Hard Parts
Three problems stand between the proposal and a working system. First, definition: “national security level” is doing a lot of work in that sentence, and the two sides do not currently share a definition of what qualifies, who decides, or how fast notification must happen. Second, verification and trust: an alert system only functions if both sides believe reports are truthful and complete, and the current environment (chip controls on one side, model theft allegations on the other) is not rich in spare trust. Third, standing: most frontier AI systems are built by companies, not states, and neither government currently has a mechanism that obliges a lab to report an incident to a foreign government. The channel as described runs between governments, several steps removed from the systems it would cover.
What to Watch
The immediate signal is the summit itself: if the Trump-Xi meeting produces a joint mention of an AI dialogue or incident channel, the mechanism moves from proposal to workstream, and technical staff follow within months. The deeper signal to watch is whether incident notification gets defined in terms concrete enough to bind lab behavior, or stays diplomatic and symbolic. And for anyone building on the assumption that AI governance remains purely domestic, note what both governments just agreed to discuss: that the interesting AI failures of the next few years will be someone else’s problem too.
Get Insanely Good at AI
The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.
Keep Reading
Why AI Hallucinates and How to Reduce It
AI hallucination isn't a bug you can patch. It's a consequence of how language models work. Here's what causes it, how to measure it, and what actually reduces it.
Trump Announces an AI Force and AI Czar, Dismissing Safety Fears as a Hoax
Trump pledged in a Truth Social post to create an AI Force and name an AI czar, dismissing safety fears as a hoax, days after every frontier lab agreed to slow development and accept embedded evaluators.
Anthropic and Accenture Commit $2 Billion to Embedded AI Evaluators
Anthropic and Accenture announced a $2 billion five-year partnership embedding Accenture evaluators inside Anthropic with employee-level access throughout the model development lifecycle, the first commercialization of the embedded-evaluator model.
Researchers Welcome Embedded Safety Evaluators, Then Ask the Obvious Question
Safety researchers welcomed Anthropic and OpenAI's commitment to embed independent evaluators inside their labs as unprecedented access, while TechCrunch's coverage asks whether the evaluators will really be independent.
Zuckerberg Breaks From the AI Pacing Consensus: Every Lab Paces Itself, No Coordination
Mark Zuckerberg rejected coordinated AI slowdown calls, arguing every lab has the responsibility and incentive to pace itself safely, splitting the frontier-lab consensus that OpenAI, Anthropic, xAI, and Google DeepMind built this week.