Cooperation Without Trust: What Trump and Xi Can Actually Agree On About AI
On September 24, Chinese President Xi Jinping is scheduled to visit the White House. President Trump announced the date in July and said artificial intelligence would be on the agenda. The two leaders had already discussed AI when Trump visited Beijing in May.
The weeks before the visit tell us more than any communiqué will. On September 8, three American security agencies accused six Chinese AI companies of copying American AI models on an industrial scale. Beijing rejected the charge. On September 12, Anthropic chief executive Dario Amodei published an essay arguing that the AI industry should slow the pace at which it makes its systems more capable. OpenAI’s Sam Altman and Elon Musk publicly supported the call. The next day, President Trump rejected it. “Whoever wins AI wins,” he told reporters in Ireland. On September 14, a spokesman for China’s Foreign Ministry dismissed the executives’ warnings as fear mongering. That same weekend, China’s Minister of State Security, Chen Yixin, published an article describing AI as a threat to the Communist Party’s hold on power.
So here is the situation. The people who build the most powerful AI systems in the United States are asking for restraint. Neither government wants to slow the strategic race. That is not the same as rejecting safety measures. Trump says guardrails are possible. Beijing says it supports global AI governance. Each government wants safety on terms that do not cost it ground.
Can two rivals that refuse to give up strategic momentum agree on anything? Probably. But the agreements will be narrow. The public should know in advance which proposals are plausible now and which are unlikely under present conditions.
What “containment” should mean
Writing on US-China AI cooperation often borrows the word “containment.” The word carries baggage. In the Cold War, containment meant George Kennan’s strategy for limiting Soviet expansion. That is not the meaning here. This is not containment of China. In this context, it is containment of specific failures of the technology: an accidental military escalation, a cyberattack by a criminal group using a frontier model, a pathogen designed with AI assistance.
Neither government has to trust the other to want those failures prevented. Each only has to see that the failure would hurt itself. The leaders need not agree about the future of AI, only that certain outcomes are unacceptable to both. That is cooperation without trust.
The Cold War analogy helps, then misleads
The United States and the Soviet Union built guardrails without trusting each other. The Washington-Moscow hotline was set up in 1963, months after the Cuban Missile Crisis showed how slowly leaders could communicate in an emergency. The 1972 Incidents at Sea Agreement set rules for how warships and military aircraft should behave near each other. Both measures were modest. Both rested on a recognition that some accidents were dangerous enough to justify limits on behavior, even between rivals who did not trust each other.
Three features of AI make the analogy weaker than it looks.
First, nuclear arms control counted relatively visible objects. Missiles, silos and warheads could be photographed from satellites. AI has physical signatures too: data centers, power consumption, chip shipments. A satellite can see a data center, not what the model inside can do. Capability resides in software, training methods and model weights, the numerical parameters that encode what a model has learned. Weights fit on a hard drive.
Second, Cold War arsenals belonged to governments. The most capable AI systems in the United States are built by private companies. Chinese firms also release open-weight models, meaning models whose weights are published so anyone can download, run and modify them. Beijing can compel its companies far more readily than Washington can. That asymmetry itself complicates verification, because each side must judge promises made by a very different kind of system.
Third, the hotline came after a near catastrophe. Guardrails usually follow a scare. The honest question for AI is whether the two sides will build anything before one happens.
What each side actually wants
The real negotiating agendas are more specific than a list of shared nightmares, and they are not symmetrical.
Washington’s priorities, as reported by Reuters, center on cyber risk. Treasury Secretary Scott Bessent, expected to lead the American side, said in May that talks should aim at keeping powerful models away from non-state actors. The United States has floated a proposal for American and Chinese AI labs to police themselves and share information to prevent AI-linked cyberattacks. According to a source cited by Reuters, Washington also worries about a future Chinese model with offensive cyber capabilities comparable to Anthropic’s Mythos.
Washington also wants to raise distillation. Distillation itself is a common technique: training a cheaper model on the outputs of a more expensive one. The dispute is over doing it without authorization and at massive scale. The September 8 advisory from the FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It said the activity likely occurred with the Chinese government’s awareness. China’s Foreign Ministry called the accusations unfounded, described distillation as normal commercial practice, and promised countermeasures.
This dispute creates a paradox. Safety cooperation depends on sharing information about how models fail and how they are attacked. But if Washington believes Chinese firms are already extracting capabilities from American models, it has reason to share less, not more. The technology that makes cooperation necessary also makes it harder.
Beijing’s priorities, according to analysts cited by Reuters, include how the United States will control the release of future frontier models, and whether Washington will restrict Chinese open-weight models. Chen Yixin’s article adds another layer. He named American models as cyber threats, warned of AI-assisted espionage and attacks on Chinese infrastructure, and warned that fake video and audio could be used to wage a propaganda war against the party.
These agendas overlap, but only in part. Both governments fear cyberattacks. Both fear criminals and terrorists with powerful tools. But the United States defines one central risk as losing its lead. China defines one central risk as losing political control at home. Any agreement has to fit inside the space where those definitions do not collide.
Even the diplomatic channel is unsettled. Reuters reported plans for an AI dialogue in mid-September, the first official bilateral AI talks of Trump’s second term. A White House official said no such meeting was planned. A Treasury spokesperson said the two sides might meet in October. Days before the summit, the American government itself was giving conflicting accounts.
Four agreements that are plausible
- Keep humans in charge of nuclear decisions, and add a channel for AI-related military incidents. In November 2024, President Biden and President Xi affirmed that humans, not AI, should control decisions to use nuclear weapons. That was a statement of principle, not a treaty. Trump and Xi could reaffirm it in their own names. It costs neither side anything.
A more useful step would be a standing channel for military incidents involving autonomous or AI-assisted systems. If a drone or an AI-assisted targeting system does something unexpected near Taiwan or in the South China Sea, each side needs a fast way to say the event was not deliberate before anyone retaliates. The 1972 agreement offers a model, not a ready-made solution. It governed visible behavior by ships and aircraft. An AI channel would face harder questions: whether a system acted on its own, who was responsible, and whether a cyber operation was involved.
- Share warnings about AI-enabled crime and terrorism. This is the American priority, and it has real value. The model is counterterrorism information sharing: narrow, specific and limited to threats from third parties.
The category needs careful edges. Criminal gangs, terrorist groups, hackers quietly working for a government, and ordinary users misusing a downloaded model are different problems. A channel limited to the first two is achievable, because each side benefits from the other’s warnings. The third is exactly where each side will suspect the other. Attribution is hard, both governments run offensive cyber programs, and the distillation dispute has soured the atmosphere.
- Screen DNA orders and test models for bioweapons assistance. Companies that manufacture DNA to order can check each order against lists of dangerous sequences before filling it. But neither country yet requires every such company to screen. In the United States, screening has been driven largely by federal funding conditions and guidance, and the framework is being revised under a May 2025 executive order. So this is a regime to build, not one to align. The two governments could each require screening and agree on shared tests for whether an AI model gives meaningful help to someone trying to build a biological weapon. An engineered pathogen does not stop at a border.
- Label machine-made media, with a firm limit. Deepfakes threaten both countries. Washington worries about fraud and elections; Chen Yixin warned about fake video of officials. There is a shared interest in labels that tell viewers when content was generated by a machine, and in detecting deepfakes used for financial fraud.
Americans should be careful here. China’s labeling rules, in force since September 2025, require visible labels and hidden labels embedded in a file’s metadata. The hidden labels identify the service provider and carry a content number. When a user requests content without a visible label, the provider must keep logs for at least six months. The rules do not, on their face, require the label to name the user. But Chinese law requires many online services to verify users’ real identities, so provider records could link content to a person. That is a risk, not a stated purpose of the rules, and it is worth being explicit.
A label that tells viewers content was machine-generated can help the public evaluate it. A system that lets authorities trace content to its creator can also be used to find dissidents. The United States can cooperate on the first. It should not help build the second.
Four ideas that are unlikely under present conditions
- A comprehensive joint slowdown. The executives’ call has run straight into both governments. Amodei himself noted that slowing by more than the size of the American lead would let Chinese projects pull ahead. Verification is the other barrier. Chip tracking, power consumption, data-center construction and independent testing can each reveal something. No existing combination provides the confidence a broad mutual slowdown would require. A narrow pause on one specific capability, such as autonomous offensive cyber tools, is more conceivable than a general one.
- Neutral, isolated joint laboratories. Shared testing laboratories in a neutral country such as Switzerland sound sensible. Testing through restricted interfaces or secure hardware can reveal some things without exposing a model’s weights. But the most thorough tests of dangerous capabilities require deep access. Neither government is likely to grant the other side’s scientists that access to its most valuable models.
- Hardware that verifies purpose. Chips are the most countable input to AI, which makes them the natural target for verification. Hardware can help establish where chips are and, with cooperation, what software is running on them. It cannot establish the military or political purpose of a computation.
- Shared mathematical definitions of “alignment.” Alignment means getting an AI system to reliably pursue what its designers intend and avoid what they prohibit. Researchers have no agreed mathematical definition of it. Two governments will not produce one at a summit.
Chips are a bargaining item, not a backdrop
Export controls were supposed to be the hard edge of the rivalry. In December 2025, Trump announced that Nvidia could sell its H200 chip to China under license. Beijing then restricted purchases to favor domestic chips. By August 2026, limited shipments had reached buyers such as ByteDance and Tencent, while Chinese approvals continued to hold back further deliveries.
In effect, both governments are using chips as leverage. Any AI safety agreement will be negotiated alongside trade concessions. That linkage can help by giving each side something to gain, or hurt if safety becomes one more concession traded for tariff relief.
The case for negotiating from strength, and its limits
The administration’s argument deserves a fair hearing. In May, Bessent said the United States can hold productive AI talks with China because America is ahead, and that the talks would look different if China held the lead. There is logic here. A leader negotiates from leverage; a laggard has reasons to stall.
Critics answer that the lead creates its own problem. If whoever wins AI wins, every safety measure looks like a tax on winning. The companies that built the American lead are now the ones asking to pace it. Domestic politics is shifting too. House Democratic leader Hakeem Jeffries has called for action to slow development. Speaker Mike Johnson has called AI a top priority for Congress.
Beijing’s messages sound contradictory but are consistent. Its diplomats call American safety warnings alarmist. Its security chief treats AI as a threat to party rule. A government can believe that a rival’s warnings are exaggerated and self-serving, and also that the technology threatens its own hold on power. Beijing’s safety concern is real. It is defined around the party.
Both sides of the American argument can be partly right. A lead provides leverage, and a reason not to spend it on restraint.
What to watch on September 24
A reaffirmation of human control over nuclear launch decisions, issued in the names of Trump and Xi, would be a small but real step. An announced channel for AI-related military or cyber incidents, with named offices responsible on each side, would be a larger one. A date for a working-level AI dialogue, with named leaders, would show that the diplomatic machinery exists. Language on DNA screening would show movement on the least controversial risk. How the two sides handle distillation, as a trade dispute or as a security accusation, will show whether it blocks everything else.
Vague phrases with no named mechanism mean nothing was agreed.
Conclusion
The United States and China will not cooperate on AI because they share values. The public positions of both governments make a broad slowdown highly unlikely. Neither will surrender strategic momentum.
What remains possible is a short list of narrow agreements that serve each side’s self-interest. Keep humans in charge of nuclear weapons. Open a line for military accidents. Warn each other about criminals and terrorists. Build screening for dangerous DNA orders. Label machine-made media without tracing the people who share it.
That is not much. But it is more than nothing. The first Cold War guardrails were modest too. They mattered on the day something went wrong.
Note:
This essay was drafted with Google’s Gemini, revised with Anthropic’s Claude, and reviewed by OpenAI’s ChatGPT. All three companies have a stake in the subject. Anthropic’s chief executive and its Mythos model are discussed above, and models from Anthropic, OpenAI and Google are among those US agencies say were distilled.
Sources
– Trump announcement of Xi’s September 24 visit (Nikkei Asia/Reuters, July 2026): https://asia.nikkei.com/politics/international-relations/us-china-tensions/trump-says-xi-will-visit-us-on-sept.-24
– China had not officially confirmed the visit (CNBC, August 31, 2026): https://www.cnbc.com/2026/08/31/china-xi-us-trump-visit-sco-brics-modi-india.html
– US and Chinese agendas for AI talks; Bessent on non-state actors (CNBC/Reuters, July 21, 2026): https://www.cnbc.com/2026/07/21/us-china-ai-talks-bessent.html
– Mid-September dialogue plans, lab self-policing proposal, Mythos-level concern, White House and Treasury responses (Reuters via Internazionale, September 4, 2026): https://www.internazionale.it/ultime-notizie-reuters/2026/09/04/exclusive-us-china-gear-up-for-mid-september-ai-safety-dialogue
– Distillation advisory (NBC News, September 2026): https://www.nbcnews.com/tech/tech-news/us-accuses-china-ai-developers-deepseek-alibaba-copying-american-ai-rcna596696
– China’s rejection of the distillation accusations: https://techjournal.org/us-accuses-ai-model-copying
– Bessent on talking from the lead (CNBC, May 14, 2026): https://www.cnbc.com/2026/05/14/us-china-ai-rules-bessent-us-lead.html
– Trump’s remarks in Ireland (Al Jazeera, September 13, 2026): https://aljazeera.com/news/2026/9/13/trump-dismisses-calls-for-ai-slowdown-from-leading-tech-ceos
– China’s Foreign Ministry response; Amodei on the size of the lead (CNBC, September 14, 2026): https://cnbc.com/2026/09/14/china-ai-slowdown-us-tech-ceos.html
– Chen Yixin’s article (New York Times via GV Wire, September 14, 2026): https://gvwire.com/2026/09/14/chinas-top-spy-chief-warns-ai-is-a-threat-to-party-rule/
– Jeffries and Johnson remarks (AP via WPRI, September 2026): https://www.wpri.com/news/politics/trump-downplays-need-to-check-ai-development-and-says-he-doesnt-want-to-cede-edge-to-china/
– China’s labeling measures, including Article 9 log retention (China Law Translate): https://www.chinalawtranslate.com/en/ai-labeling/
– Content of implicit labels (Lexology): https://www.lexology.com/library/detail.aspx?g=f15c588d-0a04-4268-852e-47981b078110
– H200 shipments to ByteDance and Tencent (GuruFocus, August 2026): https://www.gurufocus.com/news/9042544/nvidia-nvda-secures-h200-chip-exports-to-china-amid-tech-competition
– H200 export history: https://liveindex.org/technology/restrictions-on-nvidia-h200-shipments-lifted-in-china/
–
By Joe Nalven + Claude + ChatGPT + Gemini

