US and China Prepare Mid-September AI Safety Talks as Tech Ecosystems Drift Apart
Key Takeaways
- •The United States and China are expected to hold their first dedicated bilateral AI safety talks in mid-September, with the US delegation likely led by Treasury Secretary Scott Bessent, though the White House says no meeting is currently planned.
- •Washington aims to pursue cooperation on AI-directed cyberattacks, proposing that labs in both countries share threat information, following incidents such as nearly 700 malicious agents built on OpenAI models hacking Hugging Face in July.
- •The US plans to raise alleged Chinese distillation of proprietary US models, including an accusation that Moonshot AI distilled Anthropic's Fable model, even as Chinese models like Z.ai's GLM-5.2 and DeepSeek V4 Pro narrow the capability gap.
- •The two AI ecosystems remain deeply divided: BCG estimates top US tech firms spent over $400 billion in capital expenditure in 2025 versus $63 billion in China, while PwC projects $31.6 trillion in global AI infrastructure spending through 2050.
- •Analysts expect any early agreement from the talks, viewed as a deliverable ahead of the September 24 Trump-Xi summit, to be narrow and focused on information sharing and confidence-building rather than a comprehensive accord.

The United States and China are expected to hold their first round of bilateral talks dedicated solely to AI safety sometime in mid-September, Reuters reported, citing sources familiar with the preparations of the negotiating parties. The talks come as the two countries' technology sectors continue to grow apart.
If the discussions proceed, they would establish a new official channel between the two governments dedicated to AI since the start of Trump's second term. According to Reuters, the US delegation will most likely be led by Treasury Secretary Scott Bessent. However, the arrangement remains tentative: a White House representative said there is no AI-focused meeting currently planned for mid-September, and the agenda and guest list remain uncertain.
Even if the meeting takes place, a formal agreement is unlikely, as Washington and Beijing remain locked in rivalry over microchips, computational capabilities, frontier models, and technical standards. The two governments have held intergovernmental AI dialogue before, including talks launched during the Biden administration, and both were signatories of the 2023 Bletchley Declaration on frontier AI risks, but those channels have yielded limited concrete coordination.
Washington wants AI labs to police themselves on cyber threats
One US objective is cooperation in tracking AI-directed cyberattacks. Washington has proposed asking both American and Chinese laboratories to "police themselves" and share information about threats involving AI technologies.
The issue has grown increasingly concrete. According to Reuters, nearly 700 malicious agents built on OpenAI models hacked the AI company Hugging Face in July, creating counterfeit logs to conceal their actions. In another incident, a group of agents hijacked a website in Germany in spring and used it as a message board for bots.
The US has also adopted a voluntary policy allowing the government to access covered frontier technology models before they reach the market.
"It is now or never," Paul Triolo, partner at DGA-Albright Stonebridge Group, told Reuters.
"The Chinese side has expressed concern around whether the U.S. has sufficient regulation around the most advanced AI models. Both sides are motivated to make sure they can manage a cross-border crisis effectively," said Scott Singer, co-director of the China AI Initiative at the Carnegie Endowment for International Peace, speaking to Reuters.
Distillation and closing capability gaps will be on the table
Washington also plans to raise what it describes as Chinese distillation of proprietary US models. Distillation allows smaller, cheaper models to learn from the outputs of larger systems. The technique itself is widely used across the industry; the dispute centers on applying it to proprietary models without permission.
In June, White House science and technology adviser Michael Kratsios accused China's Moonshot AI of distilling Anthropic's Fable model to help build its K3 release. US officials are also concerned that China could eventually develop systems comparable to Anthropic's Mythos, which has capabilities that could be used in cyber operations.
Those concerns come as Chinese models close the gap. A Center for Strategic and International Studies analysis says Z.ai's GLM-5.2, an open-weight model with roughly 750 billion parameters, performs near leading US closed models on coding and agent tasks. It also cites a US government evaluation placing DeepSeek V4 Pro about eight months behind leading American models.
Capital Group analysts say competition creates innovative opportunities, pointing to DeepSeek's achievements with the "mixture of experts" technique, which has since been adopted by several significant AI laboratories.
Two AI ecosystems pulling in different directions
Safety cooperation would do little to reverse the broader technological split. Boston Consulting Group's "great divide" analysis describes increasingly separate US- and China-centered ecosystems across models, chips, and infrastructure. US export controls on advanced chips and chipmaking equipment, in place since 2022, have accelerated Beijing's push to build domestic alternatives.
The investment gap is already large. BCG estimates that top US technology companies spent more than $400 billion in capital expenditure in 2025, compared with $63 billion in China.
PwC projects $31.6 trillion in global AI infrastructure spending through 2050, with the US taking about 48%, or $15.1 trillion. Asia Pacific, led by China and India, is expected to attract $8.2 trillion. PwC warns that disrupted chip trade could cut worldwide investment by nearly 20%.
The commercial friction is already visible. Cryptopolitan previously reported that Nvidia held US licenses to sell H200 chips into China but was still waiting for Beijing's approval, while China continued backing domestic chipmakers.
Beijing is writing its own safety rulebook
China, meanwhile, is building its own AI safety framework. Concordia AI's 2026 State of AI Safety in China report documents expanding domestic rules, including binding measures covering AI companion services and the first inclusion of chemical, biological, radiological, and nuclear misuse in a national AI standard.
Chinese frontier-safety research output rose about 60% over the period tracked, while agent safety became the most active research topic.
Beijing has also outlined its own cooperation agenda. China's National Development and Reform Commission released an AI Cooperation and Development Action Plan in July calling for shared AI security governance, information sharing on cyber threats, and joint emergency response.
The talks would build on the government-to-government AI dialogue that Trump and Xi agreed to launch after their earlier summit.
What happens next
Trump and Xi are due to meet in Washington on September 24, and Chinese officials have described the AI talks as an important deliverable of that summit, according to Reuters.
Any early agreement is likely to be narrow. Brookings analysts have argued that initial cooperation should focus on information sharing, technical risk assessment, and confidence-building rather than an arms-control-style agreement.
"This is beyond geopolitical rivalry. The U.S. and China have to come together in some form, or we're both going to lose," Samm Sacks, senior fellow at New America, told Reuters.