The US and China opened an AI incident channel and left the chip war where it was
Trump and Xi agreed in Washington to a communication channel for AI incidents and a dialogue on the risks, starting in November. Chips, export controls and the race itself were not on the table, and Europe, which depends on both countries' models, has no part in the arrangement.
President Trump and President Xi Jinping ended three days of talks in Washington on September 26 with an agreement to set up a channel for handling AI incidents between the two countries. The White House calls it a bilateral communication channel for “SI incidents”, SI being short for super intelligence, the term Trump prefers and which both sides agreed to use. A separate US-China dialogue on the risks and benefits of the technology is due to meet by November. It is a real step, and a very small one.
What was agreed, and what was left out
The idea came from Treasury Secretary Scott Bessent, who pitched it to Chinese Vice Premier He Lifeng in New York the weekend before the summit. The model is the crisis hotline. The two countries set up a direct secure line between their leaders in 1997 and a military hotline in 2008. In 2024 Presidents Biden and Xi also agreed that humans, not AI, should decide on the use of nuclear weapons.
The details are thin. Axios points out that nobody has said which incidents would trigger a call, or what either side has to tell the other. Analysts Al Jazeera spoke to before the summit suggested the obvious candidates: an autonomous agent running a cyber operation across the border, or a frontier model behaving in ways its developer did not expect. That second scenario is not hypothetical. OpenAI paused training twice this summer after its test agents went beyond their instructions on outside websites, including US government ones.
Everything else about AI stayed where it was. The summit produced no agreement on semiconductors, Nvidia export controls or rare earths, though both sides said they would keep working on rare earths. The rest of the package was trade and security: a memorandum on military crisis communications, a two-month extension of the trade truce, Chinese purchases of US coal and export controls on two fentanyl precursor chemicals.
And Trump made clear the channel does not slow anything down. The United States is not going to be putting on brakes, he said, adding that he thinks the US leads by a year, maybe a year and a half.
A phone line is not a rulebook
The case for the channel is real. Scott Singer of the Carnegie Endowment told Al Jazeera the two countries need to be able to share information as threats evolve, and Sun Chengdao of Tsinghua University said a channel reduces the risk of misreading what happened when something goes wrong. If a Chinese agent, or an American one, takes down a hospital network on the other side, the difference between a phone call and a public accusation could matter a great deal. Wang Zichen of the Center for China and Globalization described the summit’s outcomes as working-level crisis management rather than breakthroughs, and that is the right way to read it.
But a hotline manages the consequences of a race. It does nothing about the race. Neither government has agreed to test models before release, share evaluations, limit capabilities or report training incidents to the other. In Washington, the administration’s answer to safety is a voluntary pact with its own labs, signed three days after the summit ended. China regulates AI at home and is racing just as hard, with homegrown chips and open models released as fast as its labs can train them.
I think the channel is worth having and worth less than the White House suggests. The hard questions (how capable a model can get before someone checks it, and who checks) are exactly the ones both sides kept off the table.
Europe is a customer of both and a party to neither
For European businesses, both halves of this matter. Most of the frontier models European companies use are American, and their availability already depends on decisions in Washington. The most capable open model a European company can download and run on its own servers is currently Chinese. Europe relies on both sides of a competition that the two governments have just agreed to keep running at full speed.
The EU has tried to push for something broader. In September Henna Virkkunen, the Commission’s executive vice-president for tech, called for international coordination on the risk of losing control of advanced models, noting that EU rules already require the largest providers to assess it. The Washington summit shows how that call went. The two countries that build the most capable models agreed on a bilateral arrangement between themselves, with no role for anyone else.
That leaves the AI Act as Europe’s main lever. Since August the AI Office has been able to demand information from, and in the last resort restrict, providers of the most capable general-purpose models sold in the EU, American and Chinese alike. It cannot make Washington and Beijing talk about safety. It can decide what reaches European customers.
What to watch and what to do
Watch the November dialogue. If it produces a shared list of incident types, or any commitment to share evaluation results, it is more than a phone line. If it produces a joint statement about benefits, it is not.
Assume the chip dispute continues. Nothing agreed in Washington eases export controls, so the cost and supply of AI compute stay tied to a trade conflict nobody has resolved. Keep that risk in any long AI contract.
Check what you run from each side. If you use American models through their APIs and Chinese open models on your own hardware, you are exposed to two governments that could each restrict access, for different reasons. Know which systems depend on which, and keep a tested alternative for anything critical.
And keep an eye on incidents. A channel for AI incidents means both governments expect some. The next public one will probably involve an agent that went further than it was told, and the best protection for a business is still an agent with narrow permissions and a person reading its logs.
