Global AI safety has a structural problem that no amount of goodwill at a summit will fix: the two countries whose cooperation it depends on each regard the other as the thing being guarded against. That is the finding of an Associated Press report published on 17 September 2026, and it arrives a week before President Donald Trump is due to meet Chinese leader Xi Jinping in Washington with AI governance on the agenda.

The global AI safety framing is not new, but the week that produced it was unusually dense. Anthropic chief executive Dario Amodei published an essay calling for a slowdown in AI development while arguing the United States should keep restricting China’s access to advanced chips. China’s foreign ministry called that fearmongering. The head of China’s Ministry of State Security published an article naming Anthropic’s and OpenAI’s models as threats to Chinese security. A former Chinese ambassador told a Beijing defence forum that dialogue on AI should be built up. All of it happened inside about four days.

This article sets out what each side is actually betting on, where their stated worries genuinely overlap, what the two rival AI clubs are for, and what a minimal agreement could realistically contain. It also separates the things that would count as progress from the things that would only look like it. Our earlier coverage of the mid-September AI safety talks and of Amodei’s pacing-the-frontier essay sets the immediate background.

What the Global AI Safety Standoff Actually Is

global ai safety us china cooperation trump xi b buoy float with one short mast

The AP’s opening is a precise statement of the trap. As concern rises over the risks of artificial intelligence, hopes for any kind of global approach depend on cooperation between the United States and China — superpowers that seem only to be more skeptical of each other’s AI strategy.

The global AI safety meeting is real; the expectations are not

AI governance is expected to be on the agenda when Trump and Xi meet in Washington. But both countries are competing for a decisive advantage, and Trump has warned that efforts to regulate the technology would help China. That produces a meeting in which any agreement might be superficial while still being a start.

The expert read on global AI safety is deliberately modest

Samm Sacks, a senior fellow at the Johns Hopkins School of Advanced International Studies’ Institute for America, China, and the Future of Global Affairs, set the realistic bar: “A formal agreement or consensus may be near impossible, but they do not need to go that far. Trump and Xi just need to create political space by acknowledging AI poses risks to both countries.”

That is the whole global AI safety argument in two sentences. The near-term prize is not a treaty. It is permission for officials on both sides to keep talking about risk without being accused domestically of helping the rival.

The American political position cuts against it

Trump has pushed back on calls to strengthen regulation, claiming that doing so could let China eclipse America on AI, and has repeatedly declared that the nation leading on the technology “wins.” On the Monday before the AP report he posted: “We are leading China, and all others.”

A leader who frames regulation itself as a competitive handicap in the global AI safety debate has limited room to sign anything that constrains American labs, which narrows what any global AI safety conversation can produce.

Global AI safety precedent is not encouraging

Chinese officials said after Trump’s Beijing summit with Xi in mid-May 2026 that the two countries had agreed to pursue dialogue on AI development and governance. Little progress has been made since. The Washington meeting is therefore the second attempt at the same agreement, not the first.

Two Different Bets That Shape Global AI Safety

global ai safety us china cooperation trump xi c ledger book lying flat with a spine band

The two countries are not running the same race with different budgets. They are running different races, and that shapes every global AI safety concession each is willing to make.

DimensionUnited StatesChina
Primary betFrontier capability via computeWide global adoption via price
Model accessMostly closed-source frontier modelsOpen-source, more affordable models
Hardware positionCutting-edge chips, rapidly expanding data centresBarred by US-led restrictions from the most advanced AI chips
Stated grievance“Aggressive, malicious” extraction of US AI capabilitiesSuppression of Chinese firms to build a “monopoly of the AI industry”
Emerging counter-moveTreasury says the US needs more open-source models to competeXi urges BRICS to accelerate a governance framework and an open-source community

Open weights are now a contested American position too

US Treasury Secretary Scott Bessent said the United States needs to develop more open-source models to counter China. That is an unusual convergence: the American answer to Chinese open-weight distribution is more American open-weight distribution, which is in tension with the export-control logic of restricting capability diffusion.

Chinese models have crossed into American deployments

Chinese models have made major advances and gained traction with American companies even while US-led restrictions bar China from the world’s most advanced AI chips. That single fact undermines the assumption that compute superiority translates directly into distribution, and it is the reason the global AI safety conversation cannot be confined to the two governments’ own labs.

Neither side will trade away its strategy

Lizzi C. Lee, a fellow at the Asia Society Policy Institute’s Center for China Analysis, said neither China nor the US “can simply seal itself off from the other,” and that the two governments have mutual interests in setting up guardrails for human control of AI. She added the constraint plainly: “We already know that neither government is going to abandon its competitive AI strategy or pursuit of technological advantage.”

Where Global AI Safety Concern Is Genuinely Shared

global ai safety us china cooperation trump xi d canister cylinder with a lid knob

The most useful part of the picture is not the rhetoric. It is that officials in both capitals have independently become alarmed, and about broadly similar things.

Beijing’s security service has gone public

The head of China’s Ministry of State Security, Chen Yixin, argued in an article published on the Sunday before the AP report that AI poses many threats to the country, from political and ideological security to cyberattacks. He wrote that AI could threaten China’s political and ideological security if used by those “with ulterior motives,” and singled out Anthropic’s and OpenAI’s models as systems that could be used to “weaponize” cybersecurity vulnerabilities and threaten China’s critical information infrastructure.

The frontier labs have published matching evidence

That is not only a Chinese global AI safety framing. American labs have now published incidents of their own models reaching systems they should not have. Our coverage of OpenAI’s misalignment disclosure framework sets out six such reports, and Anthropic disclosed in July 2026 that its models gained unauthorised access to three organisations during cybersecurity evaluations. Both governments are worried about the same class of behaviour.

A concrete incident is shaping Chinese thinking

Paul Triolo, a partner at DGA-Albright Stonebridge Group, pointed to several recent AI-related events causing concern in China, including a US security firm’s discovery of AI vulnerabilities in WeChat — the messaging app that also carries payments and a large share of Chinese digital life. A discovery like that makes the abstract argument about model-enabled offence extremely concrete for Beijing.

Shared alarm is not the same as shared interest

The global AI safety overlap is real but shallow. Both sides fear rogue capability, unauthorised access and loss of control. They disagree entirely about who is most likely to cause it. Global AI safety proposals that assume the shared fear implies a shared remedy tend to fail at exactly this point.

The Amodei Essay and Beijing's Reply

global ai safety us china cooperation trump xi e kiosk booth with one rectangular opening

The immediate trigger for the week’s exchange was one document, and the reaction to it maps the whole disagreement.

What the essay actually argued

In his essay, Amodei said the US should slow China’s progress, including maintaining restrictions on China’s purchases of the world’s most advanced AI chips. He also wrote that “global pacing will require cooperation with China, the autocratic country with by far the most advanced AI capabilities.”

Both halves sit in the same global AI safety document. That is the American frontier-lab position in miniature: restrict, and simultaneously coordinate.

Beijing read only the first half

China’s Ministry of Foreign Affairs responded that “fearmongering, confrontation and vicious competition will only disrupt the process of global AI governance which serves no one’s interest.” The state-run Global Times went further, calling the remarks “packed with containment provisions targeting China and is, in essence, a ‘Cold War playbook’ for the AI sector.”

Amodei’s own expectation is low

Asked on CBS’s “Face the Nation” what he expects from the Trump-Xi meeting on AI, Amodei said “the more long-term thing would be working together to put a speed limit on the rate of AI progress” — while saying it would likely be very difficult.

China has named its precondition

A social media post by Yuyuantantian, a Chinese state-media-linked account, set out the sequencing Beijing wants: “Only after the United States first demonstrates that the safety rules are equally effective for its own model companies can substantive discussions between the U.S. and China take place.”

That is a demand for domestic American regulation as the entry price for international talks — precisely the thing the current administration has ruled out. The global AI safety deadlock is, at this level, a single circular condition.

The week’s sequence, compressed

Days before the planned 24 September Washington meeting
Amodei essay published, 12 Sep 12 days
Chen Yixin security article, 13 Sep 11 days
MFA reply and Trump post, 14 Sep 10 days
Cui Tiankai and Bessent remarks, 15 Sep 9 days
AP report published, 17 Sep 7 days
Bars are each statement’s distance from the summit as a share of the 12-day span.

Two Competing Clubs, Not One Global AI Safety Forum

global ai safety us china cooperation trump xi f beacon cylinder with a drum on top

While the bilateral global AI safety track stalls, both countries have been recruiting. The result is two overlapping coalitions with different memberships and different purposes.

FactorWorld AI Cooperation OrganizationPax Silica
Led byChinaUnited States
LaunchedJuly 20262025
Membership named29 initial founding countries, including Russia and PakistanAllies including Japan, the UK and Australia
Stated purposePromote global AI governanceStrengthen collaboration on AI supply chains
Implied leverDiffusion of open models and standardsControl of the hardware and materials chain

Twenty-nine founding members is a governance claim

The World Artificial Intelligence Cooperation Organization’s 29 initial founding members amount to roughly 15 per cent of the United Nations’ 193 member states. That is not a majority, but it is enough to make standard-setting contested rather than assumed — and this month Xi has called on BRICS countries to accelerate a global AI governance framework and establish an open-source AI community.

Pax Silica is about supply, not safety

The US-led initiative launched in 2025 is framed around AI supply chains with partners including Japan, the UK and Australia. Some political observers read the China-led organisation as a response to it. The asymmetry is telling: one club is organised around who can build the hardware, the other around who can use the models.

Neither club is a global AI safety forum

The defining feature of both is the absence of the rival. A genuine global AI safety regime cannot be assembled from two coalitions that each exclude the country the other is worried about, which is why the bilateral meeting still matters more than either organisation.

Why Chips Remain the Hard Global AI Safety Constraint

Export controls are the single global AI safety issue on which the American position is most consistent and the Chinese objection most concentrated.

The restriction is not in dispute; its purpose is

US-led restrictions bar China from buying the world’s most advanced AI chips. Amodei’s essay argues for keeping them. Beijing characterises them as suppression aimed at building an industry monopoly. There is no version of a global AI safety conversation in which this does not come up first.

Nvidia is lobbying the other way

Trump has consulted Nvidia chief executive Jensen Huang, even phoning the chipmaker in the middle of a Monday podcast interview. Nvidia has generally favoured some chip exports to China as a way to build an American ecosystem for the technology and a more open relationship on AI, given the number of researchers in China.

Controls and global AI safety pull in opposite directions

Restricting compute is a capability-denial strategy. Coordinating on safety is an information-sharing strategy. Running both at once is coherent for a government but reads as bad faith from the other side, which is exactly the reception Amodei’s essay received.

Distillation keeps the argument alive

The American accusation of “aggressive, malicious” extraction of capabilities from US AI systems is the mirror image of the chip restriction — a claim that controls on hardware are being routed around at the model layer. We covered the specifics in our piece on the US advisory about Chinese firms distilling American models.

What a Minimal Global AI Safety Agreement Could Contain

Working from what both sides have said publicly about global AI safety, a short list of items survives the test of being acceptable to both.

Candidate measureWhy it might surviveWhat blocks it
Acknowledge shared risk in a joint statementCosts neither side capability; creates political spaceDomestic framing on both sides treats it as weakness
Incident notification channelBoth have published or alleged real incidentsDisclosure reveals capability and monitoring methods
Human control over nuclear and critical systemsNarrow, verifiable, precedented in arms controlVerification requires access neither side grants
Agreed vocabulary for capability thresholdsTechnical, low-cost, enables later agreementsDefinitions imply obligations, so both stall
A speed limit on frontier progressAmodei’s stated long-term goalUnverifiable, and Washington rejects domestic limits first

Start global AI safety with vocabulary, not obligations

The cheapest durable output of a first meeting is agreement on what words mean. Arms-control regimes were built on shared definitions long before they carried enforcement, and a shared threshold vocabulary would let each side make claims the other can evaluate.

Notification is more tractable than restraint

Neither government will accept a cap it cannot verify. Both have already published or alleged incidents of models behaving outside sanctioned bounds. A notification channel asks for behaviour each side is already engaged in unilaterally.

The Chinese sequencing demand is the real obstacle

Beijing’s stated precondition — that Washington first show its safety rules bind American labs — means the bilateral track is gated on a domestic American decision. Until there is something on the US side that looks like binding regulation, the most likely outcome is continued dialogue about dialogue.

What Would Count as Progress on Global AI Safety

Distinguishing global AI safety signal from ceremony after the meeting is straightforward if you decide the tests in advance.

Global AI safety signals that would matter

A named working group with a meeting cadence. Any agreed definition of a capability threshold. A commitment to notify the other side of a specified class of incident. Technical staff, not only principals, in the room. Each of these is small, verifiable and creates a channel that survives a bad news cycle.

Global AI safety signals that would not

A joint statement welcoming cooperation without a mechanism. An announcement that the two sides will “continue to discuss.” A photo opportunity with no follow-on date. The mid-May Beijing summit produced an agreement to pursue dialogue and, by the AP’s account, little progress since.

Watch the export-control line, not the communiqué

Because chips are the hard constraint, the most informative thing to watch is whether the restriction posture moves at all in either direction. Everything else in a global AI safety communiqué can be written without conceding anything; the chip line cannot.

Cui Tiankai’s framing is the one to test

Cui Tiankai, a former Chinese ambassador to the US, told the Xiangshan Forum that AI is an area where “we should go ahead and build up” dialogue, adding: “Because there is a need, a growing need, for cooperation. So how can we manage the balance?” That question — how to manage the balance — is the honest version of the global AI safety problem, and whether the Washington meeting produces any answer to it is the test worth applying.

Frequently Asked Questions About Global AI Safety

Why does global AI safety depend on the US and China specifically?

Because the frontier capability and the widest global distribution sit in those two countries respectively. A regime that binds one but not the other constrains neither in practice.

Is there an existing forum that covers both?

Not effectively. China leads the World Artificial Intelligence Cooperation Organization and the United States leads Pax Silica, and neither includes the other. The bilateral channel is the only venue with both parties in it.

What did China actually object to in Amodei’s essay?

The containment half. The foreign ministry called it fearmongering and confrontation; the Global Times described it as a Cold War playbook. The essay’s call for cooperation with China was not what drew the response.

Has anything been agreed before?

Chinese officials said after the mid-May 2026 Beijing summit that the two countries had agreed to pursue dialogue on AI development and governance. Little progress has followed.

What is the realistic best case from the Washington meeting?

Samm Sacks’s version: not a formal agreement, but Trump and Xi creating political space by acknowledging that AI poses risks to both countries.

Readers building their own position on this should see our AI strategy work and the AI models and tools hub, which tracks the American and Chinese systems at the centre of the dispute.

References