NEWS
US-China AI Safety Talks Rest on a No-New-Law Pact
The first Trump-era US-China AI safety talks are being staffed by Treasury after both governments signed G20 principles that discourage new AI-specific law.
Treasury Secretary Scott Bessent is slated to lead the first official U.S. and China AI safety talks of Donald Trump’s second term in mid-September.
A White House official said there is currently no planned AI-related meeting in mid-September. People briefed on the planning said the session is meant to land before President Trump hosts Chinese President Xi Jinping at the White House on September 24, and that both governments already signed a G20 text last week that steers them away from new AI-specific law.
A Safety Talk Led by the Treasury Secretary
Bessent is the point person on the economic relationship with China and has also called himself one of the point people on U.S. AI policy. That double brief is why American technology executives have pressed him to take the U.S. chair. It is also why a safety label on this meeting is doing a lot of work it may not be able to finish.
On May 14, speaking during Trump’s visit to Beijing, Bessent said the two AI superpowers were going to start talking. He described a protocol of best practices so that non-state actors do not get hold of the most powerful models, then added the line that still governs Washington’s posture.
What we don’t want to do is stifle innovation. So our responsibility is to come up with the highest performance calculus where we can get the most innovation and the highest level of safety.
Scott Bessent, Treasury Secretary, interview during the May 2026 Beijing meetings
In June he ranked the danger more bluntly at the Economic Club of New York. The biggest risk to AI, he said, is China getting ahead of the United States, above safety hazards and job losses. People briefed on the mid-September file say Washington wants cooperation on monitoring AI-directed cyberattacks and has floated asking U.S. and Chinese labs to police themselves and share threat information. They also say the U.S. side wants to raise alleged Chinese distillation of American models and the chance of a future Chinese system with Mythos-level cyber skills.
The Chinese lead has not been named. Names in circulation are Vice Premier He Lifeng, Bessent’s protocol match, and Ding Xuexiang, the Politburo Standing Committee member who coordinates technology, AI, and semiconductors. White House science adviser Michael Kratsios and China’s science and technology minister, Yin Hejun, could attend. The venue has not been announced.
WHAT WE KNOW
- The May bargain: After Trump met Xi in Beijing from May 13 to 15, Bessent said the two sides would set up a protocol on AI best practices.
- The U.S. chair: People briefed on planning named Bessent as the American lead for a dedicated AI session in mid-September.
- The summit date: Trump and Xi are due at the White House on September 24, and Washington intends to raise AI-directed cyberattacks there.
WHAT IS UNCONFIRMED
- The calendar: A White House official said no AI-related meeting is planned in mid-September, so the session is still a plan, not a notice.
- The room: Neither government has announced a city, a Chinese lead, or a public agenda.
- The mix of files: Chip export controls and model distillation may crowd out any shared testing work once the two sides sit down.
Putting Treasury in the chair, rather than a safety institute, is the tell. If Beijing sends He Lifeng, the meeting is a trade round that happens to say “safety” on the door card. If it sends the science ministry, there is at least a chance of a technical conversation buried in the same room.
The Carolina Principles Tell Both Sides Not to Write New AI Law
Last week in Chapel Hill, North Carolina, G20 ministers finished a two-day Innovation Ministerial hosted by the Commerce Department and the White House Office of Science and Technology Policy. China was in the room. Ministers adopted the Carolina Principles for Emerging Technologies by consensus on September 2, and Kratsios told reporters he had a great bilateral with Yin on the sidelines.
The text is not a safety treaty. It tells governments to apply existing sector-specific regulatory frameworks to emerging technologies where that fits, and to focus any new regulation on novel considerations that those frameworks cannot cover. It also backs sandboxes and experimental exemptions in supervised settings. The companion ministerial statement warns that outdated or inflexible rules can restrict innovation by accident.
THE THREE ADOPTION RULES IN CHAPEL HILL
- Old law first: Use the sector rules already on the books to govern new tools where those rules still fit the risk.
- New law as a gap filler: Write fresh rules only for novel questions the old statutes cannot reach, and do not duplicate protections that already exist.
- Test before you freeze a rule: Use sandboxes, real-world trials, and exemptions so that evidence, not a first draft of a statute, sets the path.
Kratsios had spent the opening day urging governments not to treat every new tool as a first-of-its-kind policy problem. Commerce Secretary Howard Lutnick called the consensus no small feat. The White House readout put the same thought in the language the administration wants the rest of the year to follow.
In Chapel Hill, G20 countries realized an optimistic vision for the future of emerging technologies, recognizing that flexible policy frameworks crafted to promote innovation will drive economic growth and prosperity. That is the spirit of the Carolina Principles, and that is how we will expand opportunity for Americans and people around the world.
Michael Kratsios, OSTP Director, White House statement on the Chapel Hill ministerial
That is the shared floor under the coming bilateral. Both capitals can now point to a G20 document that blesses flexible policy frameworks crafted to promote innovation and still show up in September calling the next conversation safety.
Mythos Went Dark, Then the 30-Day Window Opened
Washington’s own safety tools were built to match that floor. Hours after taking office in January 2025, Trump revoked a Biden-era order that had required developers to disclose safety-test results before putting models out. In July 2025 the White House published the Winning the AI Race action plan, more than 90 federal moves across innovation, infrastructure, and diplomacy, including a push to strip rules that slow development. The plan’s own line was that AI is far too important to smother in bureaucracy at this early stage. A later order sought to stop state laws from undercutting a minimally burdensome national framework.
June forced a harder instrument into that design. On June 2 Trump signed Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security, a voluntary process for developers to give the government access to covered frontier models for up to 30 days before release to other trusted partners. An earlier draft had asked for 90 days. The window was cut after the president said he did not want to get in the way of U.S. leadership or hand China an edge.
Anthropic had just shipped Claude Fable 5 and Mythos 5, the latter a high-skill cybersecurity model. On June 12 the Commerce Department used export-control authority to bar foreign access and forced both systems offline the same afternoon. OpenAI, in the same stretch, delayed a full public launch of GPT-5.6 at the government’s request and limited it to a small group of vetted partners.
On June 26 Commerce let Mythos 5 back to more than 100 U.S. organizations that operate and defend critical infrastructure. Anthropic said the government had notified it that its strongest cybersecurity model could be redeployed to that set. On June 30 Lutnick lifted the remaining controls after the company agreed to detect and address security risks, work with the government on future-release protocols, and report malicious activity. Eighteen days after the shutdown, the models were back. The episode was the most aggressive federal interruption of a live frontier system to date, and it still sat inside a voluntary, closed-lab process rather than a public statute.
The 30-day review only binds developers who opt in with models that meet a classified threshold. In practice that is the large U.S. labs. Open-weight systems that never enter that queue, including Chinese models that circulate without a U.S. corporate submitter, do not spend a month in front of the same agencies. The safety architecture the United States would carry into a bilateral with Beijing is, on its own terms, a peek at American closed models and an export-control club that can be picked up and put down in two weeks.
China’s Safety Record Is 5.61 Million Takedowns
Beijing’s version of safety is older, thicker, and aimed at a different harm. Chinese public policy scholar Xue Lan has called the approach agile governance: move fast, but stay inside the rules. The 2023 Interim Measures for the Administration of Generative AI Services make providers responsible for output and require models with public-opinion reach to go through Cyberspace Administration of China content-security tests before they go public. The 2021 algorithm rules and the 2022 deep-synthesis rules already told platforms to promote Core Socialist Values, label synthetic media, and identify users.
Those principles now have teeth in the product. Labelling measures issued in March 2025 took effect on September 1, 2025, with a mandatory national standard on how to mark AI text, audio, images, and video. On April 10, 2026, the CAC and four other departments issued interim measures for AI anthropomorphic interactive services, in force on July 15, adding red lines on training data, user exits, and security assessments for chatbot-style products. A national standard on basic safety requirements for generative AI sets baselines for training data, model behavior, and the tests that go with a CAC filing.
On September 2, the same day ministers signed the Carolina Principles in Chapel Hill, the CAC reported a nationwide campaign against AI misuse. Cyberspace authorities had removed 5.61 million pieces of unlawful or rule-breaking content, acted against over 49,000 accounts, and handled more than 2,400 websites and apps. The targets were fabricated news, violent or vulgar output, impersonation, and material that harms minors. Major chatbots, including Doubao, Yuanbao, Qwen, and Ernie Bot, were told to tighten training and output review.
CHINA’S FILING MACHINE
- Model registry: More than 700 generative AI models had been filed with the CAC by the end of 2025, with 48 more services added in March 2026.
- Algorithm filings: Total filings under China’s algorithm registration rules have passed 6,000.
- Label date: Visible or embedded identifiers on AI-generated content have been required since September 1, 2025.
- Next draft: A TC260 classification and grading draft for AI application security went out for comment on July 15, 2026, with a window running to September 13, 2027.
That is a real enforcement record. It is also not the record Washington means when it says safety. China’s rules police content, fraud, children, and political reliability. They do not, on the public record, mirror a 30-day pre-release cyber test of the most capable closed models. Two governments can sign the same G20 paragraph and still be describing different machines.
Geneva Already Split on Misuse and Export Controls
They have had this argument once already. On May 14, 2024, a U.S. delegation led by Tarun Chhabra of the National Security Council and Seth Center of the State Department met a Chinese group in Geneva that included the foreign ministry, the science ministry, the CAC, and the Central Foreign Affairs Commission. The session followed the Biden-Xi meeting at Woodside in November 2023. NSC spokesperson Adrienne Watson said the United States raised concerns over the misuse of AI, including by China, and wanted the channel kept open as a way to manage competition. Beijing, in its own readout, protested Washington’s restrictions and pressure.
The mismatch was structural. The American side sent technical and national-security staff. The Chinese side sent political and foreign-policy officials. Analysts who later reviewed the meeting said it stalled because the two rooms were not staffed to talk about the same object. Export controls sat on the table even when the agenda said risk. The 2026 sequel is being built with a finance minister in the U.S. chair and a possible vice premier across from him. That is not a staffing error. It is a choice.
FROM GENEVA TO THE WHITE HOUSE
- May 14, 2024: U.S. and Chinese officials hold the first government AI risk-and-safety talks in Geneva; Washington cites misuse, Beijing cites U.S. restrictions.
- May 14, 2026: Bessent, in Beijing after Trump meets Xi, says the two AI superpowers will start talking about best practices and non-state actors.
- June 2, 2026: Trump signs Executive Order 14409, the voluntary 30-day access window for covered frontier models.
- June 12 to June 30, 2026: Commerce disables, then restores, Anthropic’s Mythos 5 and Fable 5 under export-control authority.
- September 2, 2026: G20 ministers in Chapel Hill adopt the Carolina Principles; China is present; Kratsios meets Yin.
- Mid-September 2026: People briefed on planning describe a Bessent-led AI safety session; the White House says no such meeting is planned.
- September 24, 2026: Trump is due to host Xi at the White House, with AI-directed cyberattacks on the American list.
April’s OSTP memorandum sits on that same track. Kratsios said the United States has evidence that foreign entities, primarily in China, are running industrial-scale distillation campaigns to steal American AI, and that Washington would act to protect that work. Anthropic has separately described large volumes of fraudulent accounts tied to Chinese labs querying Claude. Those complaints are now candidates for the mid-September agenda. They are also the kind of grievance that turned Geneva into a recitation of export-control pain rather than a joint test protocol.
Labs Would Police Themselves Under the American Pitch
The working U.S. offer, as described by people briefed on the planning, is not a shared inspectorate. It is a request that American and Chinese labs watch their own systems for AI-directed cyberattacks and pass threat information across the gap. That fits the Carolina text, which prefers voluntary cooperation and existing tools. It also fits a Treasury-led process, because the thing being traded is access, complaint, and restraint, not a common statute.
Chinese officials have, in parallel, kept chip export controls in the same diplomatic bundle. High-end Nvidia parts remain the lever Beijing most wants moved. A safety meeting that opens on self-policing and closes on H200 licenses would not be a surprise to anyone who watched the May summit, where guardrail talk arrived in the same week as licensed chip sales.
WHAT EACH SIDE IS BRINGING
| File | Washington | Beijing |
|---|---|---|
| Stated purpose | Keep non-state actors off frontier models; watch AI-directed cyberattacks | A dedicated AI dialogue as a September 24 deliverable, with U.S. controls in the same bundle |
| Preferred tool | Labs police themselves and share threat data; voluntary 30-day U.S. reviews of opted-in closed models | CAC filings, content tests, labelling, and campaign takedowns already running at home |
| Grievance on the table | Distillation of U.S. models; a future Chinese Mythos-level cyber system | U.S. export controls on advanced chips and pressure on Chinese firms |
| Who may sit in the chair | Bessent, with Kratsios possibly in the room | He Lifeng or Ding Xuexiang, with Yin Hejun possibly in the room |
Unmonitored frontier agents can damage networks in both countries, which is the narrow slice where the two sides actually share a problem. The rest of the agenda is a contest over who sets the global meaning of the word safety, and over who has to disarm first. A meeting that spends its hours on distillation logs and entity lists will have used the safety banner to move a trade file.
September 24 Puts the Safety Label Before Trump and Xi
The leaders’ meeting is the date that cannot slip. Trump has already said Xi is coming on September 24 and that AI will be part of the conversation, while insisting that any regulation must still let American firms lead. Bessent has said the United States and China are the number one and number two superpowers in AI by a lot, and that Washington can have a full discussion because it is ahead. Chinese officials have treated a dedicated AI channel as a summit product, not a technical side meeting.
Last week’s G20 finance gathering in Asheville showed how fast the two sides still walk apart when the text gets specific. China was the holdout on the finance communique, and He Lifeng was not in that delegation, which left Bessent with little room to advance the AI file there. Chapel Hill still produced a consensus because the Carolina Principles ask almost nothing that either capital would have to repeal at home. A bilateral that tries to define safety in operational terms will not have that luxury.
Watch the nameplate on the Chinese side, and watch whether chip licenses and distillation complaints eat the clock. If the mid-September session happens at all, it will be the first dedicated government AI talks of this Trump term. It will also be a test of whether two governments that just promised not to write new AI law can do more with the word safety than schedule it.
-
NEWS4 days agoAn Oral DHB Prodrug Clears Mouse Tumors With PD-1
-
NEWS4 days agoBell Wins the Southern 500 and Closes to 12 Points
-
NEWS1 week agoApple Freezes the iOS 27 Public Beta Before the Event
-
NEWS3 days agoTrend Micro’s AI Boom Cuts Its 2026 Operating Profit
-
NEWS3 days agoHafner Bets World Models Can Skip the Robot Data War
