US and China agree to establish AI safety incident line as formal talks move to Shenzhen

The United States and China have opened a more formal channel for discussing artificial-intelligence safety risks, with U.S. Treasury Secretary Scott Bessent saying that the two sides agreed to create an AI incident line and continue work on communication protocols at another meeting in Shenzhen in approximately two months.
Bessent announced the development on September 21 after talks in New York with Chinese Vice Premier He Lifeng. According to Bessent's account of the negotiations, the proposed communication channel is intended for AI-related incidents serious enough to require direct interaction between the two governments, while subsequent discussions will examine risks including uncontrollable AI agents and malicious activity by non-state cyber actors.
China's official account independently confirms that the September 20 negotiations included a dialogue on AI-related issues, alongside economic and trade discussions. The Chinese readout does not, however, publicly describe the incident line, its activation rules or the Shenzhen follow-up in the same operational detail given by Bessent.
That difference limits what can currently be treated as a jointly documented protocol. The two governments have established an AI dialogue, and Bessent says they have agreed to create a dedicated incident-communication mechanism. There is no published bilateral technical specification yet defining what constitutes an incident, how notifications will be authenticated, what information must be exchanged or how quickly either government would be expected to respond.
··········
THE AGREEMENT ADDS AN INCIDENT CHANNEL TO THE NEW U.S.–CHINA AI DIALOGUE.
The mechanism is intended to create direct government-to-government communication when an AI event becomes serious enough to raise cross-border or national-security concerns.
The immediate development has two separate components. The first is the broader formalized U.S.–China AI dialogue. China had already publicly said that the two countries' leaders agreed to launch an intergovernmental AI dialogue and that Beijing was prepared to discuss AI risks with Washington, while continuing to disagree over technology restrictions and allegations involving model distillation.
The second component is the incident mechanism described by Bessent after the New York talks. His account moves the discussion from general diplomatic engagement toward a specific operational concept: a communication line that could be used when an AI event requires notification or coordination between the governments.
........
Element | Confirmed status as of September 21 |
Intergovernmental AI dialogue | Confirmed by both sides |
AI discussed in September 20 New York talks | Confirmed by China's official readout |
Dedicated AI incident line | Bessent says the two sides agreed to establish it |
Next AI discussions in Shenzhen | Bessent says they are expected in approximately two months |
Uncontrollable agents discussed as a risk category | Identified publicly by Bessent |
Non-state cyber actors | Identified publicly by Bessent |
Published bilateral technical protocol | Not yet available |
Public incident-severity threshold | Not yet defined |
Chinese official readout detailing the incident line | Not yet published in the material reviewed |
........
The distinction between agreement in principle and an operational system is important for interpreting the announcement. No public information currently indicates that companies or government agencies can already trigger the channel according to a defined procedure. The Shenzhen discussions are therefore expected to address at least part of the implementation layer that remains unspecified.
··········
DEFINING AN AI INCIDENT IS MORE DIFFICULT THAN ESTABLISHING THE COMMUNICATION CHANNEL.
The central technical problem is determining which model failures, agent actions or malicious uses are serious enough to require bilateral notification.
An AI incident can originate through several different mechanisms. A model may behave unexpectedly without an external attacker. An autonomous agent may exceed the scope of its assigned task after receiving legitimate access to software tools. A malicious user may deliberately use a model for cyber operations. A compromised account may provide an AI agent with credentials it was never intended to receive. An open-weight model may be modified and operated by an organization completely separate from the company that originally developed it.
These cases create different questions of attribution and responsibility. A communication protocol therefore needs more than a shared definition of “AI safety.” The governments would need to determine whether notification depends on the consequences of an incident, the capability of the system involved, the identity of the operator, the geographic impact or some combination of those factors.
Bessent has specifically identified uncontrollable agents and malicious non-state actors as subjects for the next stage of the talks. China's public position is broader: Beijing has acknowledged recurring risks associated with rapid model development while continuing to dispute U.S. restrictions and allegations involving Chinese AI companies.
That leaves a potentially workable but narrow area for cooperation. The two countries do not need to agree on semiconductor export controls, model competition or industrial policy in order to exchange information about a sufficiently serious AI incident. They do need enough common terminology to determine when communication should begin and what information can be trusted once it does.
··········
AN OPERATIONAL INCIDENT LINE REQUIRES AUTHENTICATION, SEVERITY LEVELS AND ESCALATION RULES.
The following framework is a Data Studios analysis of the minimum operational questions that would need to be resolved; these elements have not been announced as components of the bilateral agreement.
A direct communications line has limited practical value if governments cannot determine when it should be activated or who has authority to use it. The first requirement is authentication: an incident notification itself could become a target for manipulation, so both governments need a mechanism for confirming that an alert originates from an authorized counterpart.
The second is severity classification. Routine model errors cannot reasonably trigger interstate communication. A workable system would need a threshold separating ordinary product incidents from events with systemic, cross-border or national-security implications.
The third is attribution confidence. AI systems frequently operate through cloud services, external tools, third-party accounts and infrastructure spread across several jurisdictions, so initial incident reports may be technically accurate while attribution remains uncertain.
The fourth is private-sector escalation. Most frontier models and the infrastructure supporting them are operated by companies, meaning any government-level mechanism will eventually need a process for receiving relevant information from AI laboratories, cloud providers or infrastructure operators.
........
Data Studios operational framework | Function |
Authentication | Confirms that an alert genuinely comes from the counterpart government |
Incident threshold | Determines when an event becomes eligible for bilateral notification |
Severity classification | Separates manageable operational failures from systemic events |
Attribution confidence | Communicates how strongly an actor, model or infrastructure provider has been identified |
Minimum technical disclosure | Defines the information required for the counterpart to evaluate the incident |
Private-sector escalation | Connects AI companies and cloud providers with government responders |
Acknowledgement time | Establishes how quickly an alert must be received and confirmed |
Containment updates | Provides structured communication while an incident remains active |
Confidentiality rules | Protects sensitive vulnerabilities, model information and intelligence |
Closure and review | Establishes when an incident is considered resolved and how lessons are recorded |
........
These requirements become harder when the model developer, compute provider, user and affected systems are located in different countries. A U.S.-developed model can operate through infrastructure outside the United States. A Chinese model can be downloaded, modified and deployed by an independent organization elsewhere. An autonomous cyber operation can move through infrastructure in multiple jurisdictions before either government understands its origin.
The bilateral mechanism therefore does not eliminate attribution problems. Its narrower function would be to create a recognized path for communication while those problems are being investigated.
··········
SHENZHEN WILL DETERMINE HOW FAR THE AGREEMENT MOVES FROM DIPLOMATIC DIALOGUE TO INCIDENT PROTOCOL.
The next technical milestone is the publication or confirmation of rules describing when the channel is activated and what happens after an alert is sent.
Bessent says senior U.S. and Chinese officials expect to continue the AI discussions in Shenzhen in approximately two months, with the development of communications protocols among the subjects under consideration. China's official September 21 account confirms that AI was included in the New York discussions but provides no equivalent public description yet of the Shenzhen agenda or incident mechanism.
That asymmetry should remain visible in any assessment of the agreement. At present, the existence of the bilateral AI dialogue is confirmed by both governments, while the more detailed description of the incident line and planned protocol work comes from Bessent's account.
The operational test will therefore come later. A functioning incident mechanism would require the governments to specify notification thresholds, authenticated contacts, information-sharing procedures and escalation rules without necessarily resolving their wider disagreements over chips, model access or technology policy.
Until those elements are published, the September agreement is best described as the beginning of an AI crisis-communication framework, rather than a fully deployed AI safety hotline.
··········
FOLLOW US FOR MORE.
·····
DATA STUDIOS
·····
[datastudios.org]




