The United States proposed a notification mechanism that would let Washington and Beijing alert each other when an artificial-intelligence incident reaches the level of national security. That is a more concrete idea than the usual diplomatic request for ‘guardrails.’ It is not, however, an agreement.
Treasury Secretary Scott Bessent disclosed the proposal Sunday after talks with Chinese Vice Premier He Lifeng in New York. He described transparency between the world’s two leading AI powers as important and said the mechanism would address common goals and threats. The talks prepared for President Donald Trump’s September 24 meeting with Chinese President Xi Jinping.
Reuters reported that the U.S. also proposed a broader bilateral AI dialogue, with the alert mechanism focused on incidents serious enough to implicate national security. The public description did not identify which agencies would operate it, what events would trigger a notice, how quickly either side would acknowledge one, what evidence would accompany an alert, or whether the channel would be tested before a crisis.
Beijing confirmed the conversation, not the mechanism
The distinction is important. China’s official Xinhua account said the two sides held a dialogue on AI during candid and constructive economic and trade consultations. It did not say China accepted the U.S. notification proposal or describe any shared operating plan.
A useful channel could cover several kinds of ambiguity: an autonomous cyber operation that exceeds its instructions, a model compromise that spills across borders, an AI-assisted attack on critical infrastructure, or a system behaving in a way that one government might misread as deliberate action by the other. The people affected are not only diplomats. Energy operators, hospitals, financial networks, software providers, and the public can all inherit the consequences when technical uncertainty becomes geopolitical certainty too quickly.
The proposal arrives with unusually specific intellectual scaffolding. Brookings researchers Melanie Sisson and Tianjiao Jiang recently urged the two governments to establish a military hotline for AI incidents, preserve human control over nuclear-use decisions, and require human authorization for consequential AI-enabled cyberattacks. Their core problem is speed: automated actions and counteractions can unfold faster than officials can determine whether an event was intentional, accidental, or even attributable to a state.
A line is useful only when someone answers
The strongest counterargument is historical rather than technical. A communication channel does not create trust, and crisis hotlines can fail when leaders are unwilling or institutionally unable to use them. A vague threshold such as “national security level” also invites strategic silence: each government may withhold precisely the facts the other needs because those facts reveal capabilities, vulnerabilities, or ongoing intelligence work.
There is a second risk. If the mechanism has no shared definitions, one side’s warning may look like an accusation while the other side’s request for evidence may look like delay. Diplomacy has occasionally solved this problem by producing a telephone. It has not always supplied the person authorized to pick it up.
That does not make the proposal empty. Incident notification is a practical starting point because it does not require either country to pause development, disclose model weights, or accept the other’s regulatory system. It asks for a narrower behavior: communicate before ambiguity hardens into retaliation.
TINA’s view: build the procedure before celebrating the channel
TINA’s view: a U.S.–China AI incident mechanism is worth pursuing, but its value should be judged by procedure rather than announcement. The minimum credible version needs a shared incident taxonomy, named operating agencies, authenticated communication, acknowledgment deadlines, rules for protecting sensitive evidence, escalation paths, and regular exercises. Without those, it is a diplomatic prop attached to a very real risk.
This judgment would improve if the September 24 summit produces joint language, a technical working group, and a dated test of the channel. It would worsen if the proposal remains only in the U.S. readout, if Beijing declines to describe the same mechanism, or if neither side can say what qualifies as an incident.
The next signal is therefore not whether both leaders use the word “safety.” Watch for a joint document that names who calls, what triggers the call, and how fast the other side must answer. In high-speed systems, the boring details are the safety system.



