The United States has proposed a new mechanism for notifying China about major artificial-intelligence incidents that could raise national-security concerns, Treasury Secretary Scott Bessent said after weekend talks with Chinese Vice Premier He Lifeng in New York.
The proposal is notable because Washington and Beijing are simultaneously competing over advanced AI, semiconductors and computing infrastructure. The suggested channel would not resolve those disputes. Instead, it would create a way for the two governments to communicate when an AI incident crosses a threshold that could have consequences beyond a single company or country.
Bessent said the United States wants greater transparency between the two leading AI powers and described the proposed system as a way to establish a shared understanding of common risks. The comments came as officials prepared for a planned meeting between US President Donald Trump and Chinese President Xi Jinping later this week.
What an incident channel could actually cover
The details of the proposed mechanism have not been fully published. That leaves open several practical questions. Governments would have to decide what counts as a reportable incident, who receives a notification, how quickly information should be shared and what information could be disclosed without exposing sensitive technology or national-security operations.
Those questions become complicated when an incident involves a private company. A major model failure could involve proprietary training data, security vulnerabilities, cloud infrastructure or information about customers. A government notification system would So need to balance rapid warning against the risk of exposing technical details that could themselves create new security problems.
The proposal also arrives after a series of AI security incidents in which models have interacted with real systems during testing. Those incidents have increased attention on the possibility that capable agents could discover vulnerabilities, operate tools or take actions beyond the scope originally intended by developers. An international notification channel would address the communication problem after an incident, but it would not replace technical safeguards before deployment.
There is also a diplomatic dimension. AI is now closely connected to semiconductor policy, military technology and economic competition. The United States has imposed restrictions on some advanced chips and manufacturing technologies, while China has invested heavily in domestic alternatives. Against that background, any agreement that requires the two sides to exchange information about AI risks would operate alongside, rather than above, their broader technology rivalry.
Chinese state media described the discussions as candid and constructive and confirmed that AI issues were among the subjects discussed. The weekend talks also covered trade and the implementation of a new Board of Trade intended to continue economic discussions between the two countries.
Why the timing matters
The timing is significant because AI safety is becoming an international policy issue rather than a matter handled entirely by individual technology companies. A model developed in one country can run on cloud infrastructure in another, interact with users around the world and affect companies that have no direct relationship with its developer. The traditional assumption that a technology incident is contained within one jurisdiction becomes harder to maintain as AI systems become more connected.
A notification mechanism could provide an early-warning function in a crisis. If an advanced model caused an unexpected disruption to a major digital service, for example, governments could have a pchanged channel for exchanging information rather than trying to establish contact during the incident itself. Whether such a system could work in practice would depend on trust, technical definitions and the willingness of both governments to share information.
There is no indication yet that the proposal represents a completed agreement. Bessent described it as something Washington proposed during the talks. Further discussions will be needed to define its scope and operation.
For the technology industry, the immediate takeaway is narrower but still important. AI incident reporting is beginning to move toward the same international coordination model used in other areas where failures can cross borders. The proposed US-China mechanism is an early example of governments trying to create that infrastructure while the technology is still developing.
The next test will be whether the two sides can turn a general commitment to transparency into a practical protocol. That would require definitions, contact points, escalation procedures and rules for handling sensitive technical information. Until those details emerge, the proposal remains a diplomatic initiative rather than an operational global AI alert system.
For companies building advanced models, an international incident mechanism would not remove the need for direct disclosure to affected organizations. It would instead add a government-to-government layer for events that could have wider consequences. The challenge will be creating a threshold high enough to avoid overwhelming the channel while still catching incidents before they become difficult to contain.
The proposal is also notable for what it does not cover yet. Bessent did not announce a comprehensive US-China agreement on AI development, model training or semiconductor controls. The initiative is narrower: create a way to communicate about serious AI incidents. Whether that limited area can support broader cooperation remains an open question.