The United States and China are exploring an unusual form of cooperation in one of the world’s most competitive technologies: artificial intelligence.
As President Donald Trump and Chinese President Xi Jinping meet in Washington, officials from both countries are discussing the possibility of establishing a mechanism that would allow them to notify one another about significant AI-related incidents.
The idea sounds straightforward.
The details are anything but.
U.S. Treasury Secretary Scott Bessent proposed an AI “notification mechanism” during meetings with Chinese Vice Premier He Lifeng in New York over the weekend. The proposed framework is intended to create a channel for discussions involving AI safety, national security and potentially serious incidents associated with increasingly powerful systems.
But there is still no clearly defined operating manual for this proposed system.
That is where the biggest questions begin.
What exactly would qualify as a reportable AI incident?
Would the system cover major cyberattacks powered by AI? Would it include evidence that an AI model was being used to develop biological threats? Would the two countries notify each other about a model losing control, attempting unauthorized actions or interacting with critical infrastructure?
And who would decide when a situation was serious enough to report?
Those questions matter because artificial intelligence has moved far beyond a traditional software debate.
Advanced AI systems are increasingly capable of writing code, analyzing large quantities of information, automating workflows and operating tools. Policymakers and researchers have consequently raised concerns about the technology being used for cyberattacks, disinformation, biological misuse and attacks against critical infrastructure.
The Associated Press reported that officials and experts in both countries are increasingly focused on shared AI risks even as Washington and Beijing compete aggressively for technological leadership. Those concerns include cyberattacks, biological misuse, loss-of-control scenarios and potential threats to finance, transportation and energy infrastructure.
That creates the central paradox of the proposed mechanism.
The United States and China are competing over AI — while simultaneously discussing whether they should cooperate to prevent the technology from producing catastrophic outcomes.
This is not the first attempt.
Reuters reported that the idea of an AI dialogue had already been discussed in May, but a formal forum had not yet been established. The latest proposal is an effort to turn those earlier conversations into something more structured.
The distinction between a “dialogue” and a formal notification mechanism is important.
A dialogue can be broad and exploratory.
A notification system requires rules.
Governments would need to determine which agencies participate, how information is verified, how quickly notifications must be delivered, whether sensitive technical details can be shared and what happens when one country believes the other has failed to disclose a serious incident.
That is difficult even among allies.
It becomes significantly more complicated between geopolitical competitors.
Trust is perhaps the biggest obstacle.
Washington and Beijing have sharply different views about technology, national security and strategic competition. The United States has imposed restrictions on China's access to certain advanced AI chips and semiconductor technologies, while China has accelerated efforts to build domestic alternatives.
At the same time, Chinese AI firms have rapidly increased their capabilities.
Companies such as DeepSeek and Moonshot AI have emerged as major names in China's AI ecosystem, while Alibaba, Tencent and other large technology groups continue investing heavily in their own models and infrastructure.
Those developments are taking place alongside accusations from American AI companies that some Chinese developers have improperly used outputs from U.S. AI systems.
Anthropic recently alleged that Chinese AI developers had engaged in large-scale efforts to extract capabilities from Claude through massive numbers of interactions. Chinese officials have rejected such accusations as exaggerated.
That makes transparency particularly difficult.
Imagine a scenario in which one government believes another country's AI system is being used to conduct a sophisticated cyber operation.
Would the incident be reported through the proposed channel?
Would the other side accept the technical evidence?
Would the information be handled separately from intelligence operations?
And could the notification channel itself become a target for espionage?
These are not theoretical questions.
An AI communication mechanism involving national-security incidents would likely require careful separation between safety cooperation and sensitive military or intelligence information.
That may explain why officials have emphasized a narrow objective rather than a comprehensive AI treaty.
The U.S. proposal appears focused on creating communication around risks rather than attempting to eliminate competition.
Reuters reported that discussions around advanced AI-chip export restrictions were not part of the latest Treasury talks, illustrating that the proposed safety dialogue exists alongside — rather than replacing — broader technology restrictions.
That separation could prove important.
The United States may want China to communicate quickly if a dangerous AI incident occurs without reducing its ability to restrict technologies it considers strategically sensitive.
China, meanwhile, has its own concerns about U.S. technology, national security policies and the global AI system.
Chinese officials have also criticized what they describe as efforts by Washington to limit China's technological development.
The proposed mechanism therefore resembles an effort to create guardrails around competition rather than end the competition itself.
That concept has historical precedents.
During the Cold War, rival powers established communication channels designed to reduce the risk of misunderstandings escalating into catastrophic confrontations.
Artificial intelligence is obviously different from nuclear weapons, but the underlying diplomatic principle is similar: when rivals possess technologies capable of producing rapid and potentially unpredictable consequences, communication can help reduce the risk of miscalculation.
The challenge is deciding what should trigger that communication.
AI systems do not always fail in ways that are immediately obvious.
A model may generate harmful instructions. An autonomous system might interact with software in an unexpected way. An AI agent could be manipulated by malicious prompts. A cyberattack may combine traditional hacking with automated AI capabilities.
Determining whether any individual incident deserves international notification could be enormously complicated.
There is also the question of speed.
AI systems operate at digital speeds. Governments often work at diplomatic speeds.
A useful notification mechanism would need to bridge that gap.
It would also need to establish a degree of credibility. If notifications become politicized or are used primarily to accuse the other country of misconduct, the system could quickly lose value.
For that reason, the first stage may be less ambitious than the phrase “AI hotline” suggests.
The countries could initially use the mechanism simply to exchange information, identify points of contact and establish procedures for escalating serious incidents.
Even that would represent a meaningful development.
The global AI industry has no single government, regulator or authority capable of managing all frontier-AI risks.
The largest AI laboratories are spread across different countries, operate under different legal systems and compete commercially.
That makes international communication increasingly relevant.
The Trump-Xi summit gives the proposal a high-profile political backdrop, but the hard work would come afterward.
Officials would have to decide what the mechanism covers, who participates, what information can be shared and how disagreements are handled.
The proposed channel may eventually become an important part of AI governance.
Or it may remain a diplomatic framework that never develops into an operational system.
At this stage, both possibilities remain open.
What is clear is that Washington and Beijing have recognized an unusual reality: the same technology that has become a centerpiece of their strategic competition is also creating risks that neither country can completely manage alone.
The AI race is still accelerating.
But alongside the race, governments are beginning to build something else — a way to call each other before an AI incident becomes an international crisis.
