The United States has proposed that China join a system for notifying each other of AI incidents that affect national security. After talks in New York on September 20, 2026 with Chinese Vice Premier He Lifeng and others, US Treasury Secretary Scott Bessent described the AI dialogue and a follow-up meeting. Ahead of a summit between President Trump and President Xi Jinping scheduled for the 24th, the move would turn the government-to-government dialogue agreed in May into concrete procedures for communicating during an incident. However, China's published statement does not mention a notification system, and the operating conditions remain unclear: what counts as an incident, when it must be reported, and to whom.
Separating the dialogue from the notification system in the US and Chinese records
At a press conference on the 20th, Bessent said the two sides had discussed a US-China AI dialogue mechanism and agreed to meet again. He then explained that the notification system was proposed by the US side. In Bessent's remarks as carried by Reuters, the agreement to meet again and the proposal for a notification system appear in separate sentences.
China has also acknowledged that AI was on the agenda. An announcement carried by Xinhua and posted by the Ministry of Commerce on the 21st says He, Bessent and US Trade Representative Jamieson Greer discussed economic and trade issues and also held a dialogue on AI. It does not mention the scope of incident notification or when it would be implemented.
The May 2026 agreement on a government-to-government AI dialogue was followed on September 20 by the US side's explanation of a specific proposal on incident notification. China's published account of the same day's talks says only that AI was discussed.
| Date of statement or remarks | Who said what | Subject of agreement or proposal |
|---|---|---|
| May 19, 2026 | China's Foreign Ministry described the exchange between the leaders during Trump's visit to China | Agreed to hold a government-to-government AI dialogue |
| September 20 | Bessent spoke after the New York talks | Agreed to meet again. The US proposed a notification system |
| Published September 21, regarding the talks on the 20th | China's Ministry of Commerce posted an account of the talks | States that AI was discussed. No mention of a notification system |
The table compares the AI-related answer in the Chinese Foreign Ministry's May 19 press conference, the US remarks above and the Chinese statement, by date and subject of agreement. The differences between the published accounts do not allow us to conclude that nothing was agreed privately, or that China rejected the notification system. Nor, on this evidence alone, can we read it as a system that has begun to operate.
On the 21st, the US side offered a more concrete explanation. According to Bessent's remarks on CNBC, as reported by Reuters, the two countries will formalize a dialogue that includes an incident contact point, and plan to meet in Shenzhen, China, in about two months to discuss AI risks and communication procedures. He cited uncontrolled agents and cyber threats from non-state actors as examples. This is the US side's stated plan for future talks, and should be distinguished from the publication of a joint document setting notification criteria or the date a contact point becomes operational.
AI dialogue is not new; this time the focus is contact during incidents
US-China AI safety talks have a history that predates this one. In its May 14, 2024 announcement, the US National Security Council (NSC) said the two governments would meet in Geneva to exchange views on how each understands and addresses the risks of advanced AI. Those talks followed the November 2023 summit, and at the time the central agenda item was understanding each other's perception of risk.
At this year's May summit, too, China's Foreign Ministry announced agreement on a government-to-government AI dialogue. Describing the September developments as the two countries "discussing AI dangers for the first time" would therefore obscure what has actually advanced this time.
The US proposal is aimed at communication when an incident occurs. It tries to move from a forum for exchanging views in normal times to a procedure by which the side that detects an anomaly informs the other country. If realized, it could shorten the period in which one side does not know what the other has grasped. But a mechanism for notifying is separate from the capacity to stop harm, and the two must be built separately.
It is also premature to link progress in safety talks to any easing of the technology competition. According to Reuters' report of the 20th, Greer said export controls on advanced AI chips and semiconductor manufacturing equipment were not on the agenda of these AI talks. In the explanations given so far, sharing incident information and changing the range of technology the other country can obtain are treated as different issues.
What counts as an incident to report?
Even with a stated scope of "AI incidents affecting national security," the point at which notification is required is not self-evident. Does a side report only after confirming harm? Or does it report signs of loss of control even before harm occurs? That difference determines whether notification is an after-the-fact report or information for prevention.
A useful reference is the common reporting framework for AI incidents that the Organisation for Economic Co-operation and Development (OECD) published on February 28, 2025. The report distinguishes incidents in which AI caused actual harm from events that could lead to incidents. It also sets out 29 reporting items, of which 7 are designated as required within the framework. The US and China have not adopted it as a specification, but it offers material for thinking about what needs to be aligned when sharing incident information.
Table 2.2 of the report lists items such as a description of the incident, its relationship to AI and supporting materials. Severity and type of harm are also required items. Simply saying that "AI was involved" makes it hard for the recipient to judge what the danger means.
For example, the target to stop differs between a case where an AI agent keeps performing unintended actions and a case where a person is deliberately misusing AI. In the former, permissions and the execution environment would need to be examined; in the latter, it would be necessary to understand the user's behavior and the route of intrusion. This is an assumption for thinking about operations, but the OECD also classifies the relationship between AI and an incident into categories such as direct cause, contributing factor, and human overreliance or misuse.
Even under the single label "incident," cause, harm and imminent danger are separate pieces of information. If the US-China notification system targets serious cases affecting national security, they will need to decide which of this information goes into the initial report, and whether to notify even before actual harm is confirmed. The published statements available now do not show where that line is drawn.
What remains once contact points are set
The OECD report states that while it establishes a common reporting format, it does not provide specific guidance on the preventive or corrective measures to take after an incident. Assembling and sending information is one job; being able to respond once it is received is another, and in institutional design they are separate tasks.
When assessing the US-China concept, what happens before and after the contact point matters more than the name of the contact point itself. First, information held by the companies or research institutions that detect a case must reach a responsible domestic agency. That agency decides whether to notify abroad, and the other side receives it and passes it to an organization able to respond. If information stops anywhere along this chain, a government-to-government contact point alone will not deliver the warning.
Information held by companies includes the conditions for reproducing a danger and records of operations, but it may also include details that could be turned into attacks, as well as confidential material. Work is needed to separate what must be shared for the other side to defend itself from what would spread the danger. Recording the model name and version, the environment in which the incident occurred and the extent of harm would be a starting point for that judgment. These are practical issues derived from the notification proposal, not requirements the US and China have already agreed on.
Speed and accuracy must also be balanced. Waiting until the cause is fully established may delay the warning. But conveying an uncertain initial report as a firm conclusion could mislead the recipient's judgment. Early contact is useful only if there is a procedure that separates confirmed facts from findings still under investigation and allows later correction.
In the next round of talks, which the US side expects in about two months, the question is how far the notification targets, deadlines, responsible contact points and handling of shared information will be made concrete. If information flowing from companies to governments can be connected to government-to-government contact, even two competing countries would gain a way to report a serious anomaly in time for the other to act on it.
