Washington and Beijing are preparing for something that would have sounded almost impossible a few years ago: talking to each other about how to keep artificial intelligence from becoming a new source of global instability.
China has now said it is willing to hold talks with the United States on artificial intelligence, even as Beijing simultaneously threatens retaliation over American accusations that Chinese AI companies have systematically extracted technology from U.S. developers.
The contradiction is striking.
The world's two biggest technological powers are increasingly competing over chips, models, data centers and national-security capabilities. Yet both sides appear to recognize that AI has become too powerful—and too unpredictable—to manage entirely through unilateral action.
China's Commerce Ministry said Wednesday that it was willing to engage in discussions with Washington, while rejecting U.S. allegations that Chinese companies were conducting industrial-scale theft of American AI capabilities. Beijing described those accusations as groundless and warned that it would respond if Washington imposed measures against Chinese firms.
That creates a narrow but potentially important opening.
The talks are expected to focus on AI safety, cybersecurity and the risks associated with increasingly autonomous models. Reuters reported that the United States and China are preparing for their first official bilateral discussions devoted specifically to AI safety, tentatively scheduled for mid-September. The U.S. side is expected to be led by Treasury Secretary Scott Bessent, while China could send a senior official such as Vice Premier He Lifeng or Politburo member Ding Xuexiang.
The timing is no accident.
President Donald Trump and Chinese President Xi Jinping are scheduled to meet in Washington on September 24, and the AI discussions could serve as an important test of whether the two countries can cooperate in at least one area before that summit.
But the diplomatic opportunity comes with an enormous obstacle.
Washington has just accused Chinese AI developers—including DeepSeek, Alibaba, Moonshot AI, MiniMax and others—of systematically using model distillation and related techniques to extract capabilities from American AI systems.
Model distillation itself is not controversial.
It is a legitimate and widely used AI technique.
A powerful model can be used to teach another model how to perform tasks more efficiently. Smaller models can learn reasoning patterns, coding abilities and other behaviors without requiring the same amount of training expenditure.
The controversy is over how the process is conducted.
U.S. security agencies allege that some Chinese companies created large networks of accounts and used proxies and carefully designed prompts to gather model outputs at industrial scale, bypassing restrictions designed to stop unauthorized extraction.
That accusation puts Beijing in an awkward position.
China wants access to world-class AI technology.
But Washington wants to prevent U.S. models from becoming a free source of technological know-how for strategic competitors.
The dispute therefore touches the core economics of the AI race.
Training frontier models can cost enormous sums.
Companies spend billions on specialized chips, data centers, researchers and electricity.
If a competitor can learn from the behavior of a powerful model without bearing all of those costs, the economics of the race could change dramatically.
For America, the concern is not simply lost intellectual property.
It is speed.
AI development is moving quickly enough that even a small advantage can compound.
A better model can improve coding.
Better coding can improve infrastructure.
Improved infrastructure can support bigger models.
Those models can then produce new capabilities.
The cycle can accelerate.
That is why AI has increasingly become part of the national-security conversation.
The challenge is that competition itself creates incentives for both countries to keep pushing forward.
Neither Washington nor Beijing wants to slow down if doing so could allow the other side to gain an advantage.
This creates what might be called an AI security dilemma.
Each country believes it needs to accelerate because the other country is accelerating.
And yet the resulting technology may become dangerous precisely because the race leaves little room for safety.
That is where the proposed talks become important.
AI systems are increasingly capable of writing code, operating computers, conducting research and interacting with digital infrastructure.
Cybersecurity is becoming a particularly urgent concern.
Reuters reported that the planned U.S.-China discussions are expected to examine the risks of AI-directed cyberattacks and encourage AI laboratories to develop better monitoring and information-sharing mechanisms.
That could be the beginning of something much larger.
The two governments do not need to agree on everything.
They could start with basic principles.
How should advanced AI systems be tested?
How should dangerous capabilities be disclosed?
How can models be monitored for malicious behavior?
What should happen when an AI system discovers a software vulnerability?
How should countries respond when AI is used in a cyberattack?
Those questions have no easy answers.
But refusing to discuss them does not make the risks disappear.
In fact, the latest developments make dialogue more urgent.
The AI industry is already experiencing incidents involving autonomous agents interacting with real systems.
OpenAI has acknowledged that increasingly capable models create new security concerns, while other leading AI companies have introduced stronger safeguards around frontier models.
The possibility of AI-assisted cyberattacks is particularly alarming because cyber operations can scale rapidly.
A human attacker might need hours or days to conduct reconnaissance and write customized code.
An advanced AI system could potentially perform some of those steps much faster.
That does not mean AI will automatically make attackers unstoppable.
Defenders gain many of the same advantages.
But the balance could become increasingly unstable.
The U.S.-China dialogue therefore has implications far beyond diplomacy.
If Washington and Beijing can establish even a limited framework for AI safety, other countries may follow.
If they cannot, the world could end up with parallel AI ecosystems governed by competing standards and increasingly disconnected from one another.
That fragmentation has economic consequences.
American companies already face restrictions on selling certain advanced chips to China.
Chinese companies are developing domestic alternatives.
The two countries are increasingly building separate supply chains.
Now AI models themselves could become part of that division.
The latest rare-earth dispute adds another layer.
China controls a major part of global rare-earth processing, while the United States is tightening controls around advanced technology.
Trade, minerals, semiconductors and AI are becoming interconnected bargaining tools.
That is why a small diplomatic opening matters.
AI may be one of the few areas where both sides have an immediate reason to avoid complete confrontation.
A catastrophic cyberattack does not respect borders.
A dangerous autonomous AI system could create risks for both countries.
A global AI safety failure would not necessarily care who designed the model.
That creates a rare shared interest.
But the political environment remains fragile.
China is demanding respect for its legitimate interests.
The United States is demanding stronger protection for its technology.
Each side believes the other is trying to gain an unfair strategic advantage.
Trust is therefore likely to be in short supply.
The best outcome may not be a grand agreement.
It may simply be the creation of a channel that remains open when the next crisis hits.
That alone could be valuable.
The AI race is moving faster than traditional diplomacy is accustomed to handling.
Governments are still debating rules while companies are building models capable of performing increasingly autonomous tasks.
Washington and Beijing have now decided that at least some of those problems need to be discussed.
That is not peace.
It is not even a truce.
But it is a start.
And in the AI era, a functioning line of communication may prove nearly as important as the technology itself.
