Product2 publishers3 min readPublished
Bessent pitched Beijing a US-China AI incident notification channel
Treasury Secretary Scott Bessent put a mutual AI incident notification channel to Chinese officials in Manhattan on Sunday. Beijing has not said yes, and the record's only route to frontier labs is a request that they share threat information.
The Product Desk · Product desk

What happened
- Treasury Secretary Scott Bessent proposed to Chinese officials that the two governments notify each other of artificial intelligence incidents serious enough to threaten national security.
- Bessent and trade representative Jamieson Greer put it to Vice Premier He Lifeng and negotiator Li Chenggang on Sunday at JPMorgan's Manhattan headquarters, in space the bank lent them.
- Beijing did not say whether it accepts, and Chinese officials have not described the mechanism. The two sides agreed to meet again on AI, with no date, place or format set.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint With no published threshold for a qualifying incident, the scope is set by whoever writes the timeline, and a lab cannot build a reporting runbook for a filing it cannot size.
- exposure A postmortem written for engineers and one written knowing a second government may read it are different documents. The Nikkei-reported plan to ask laboratories for threat information puts labs on the second side of that line.
- contradiction Beijing is being offered a notification duty while chip export controls stay closed, and Sacks has already said China is very unlikely to join a global agreement. Acceptance would be the surprising outcome.
- decision Lab leaders who asked Washington to build international coordination now have a specific version to endorse or refuse, with no counterparty commitment attached to it.
Somebody at a frontier lab owns the incident template, and its first field asks who needs to know. Right now the answers are a legal team, an affected customer, sometimes a regulator with jurisdiction. The proposal Scott Bessent put to Chinese officials on Sunday would eventually add a line above those [13], and the record does not say which incidents reach it [1].
For a channel like that to change what anyone writes down, two things have to exist: a definition of the reportable event, and a named party who files it. By The Next Web's account, Bessent presented the idea as a channel for communication and nothing resembling a treaty [15]. The only route to the labs in the record comes from a Nikkei report this month, cited by The Next Web. That report says the American side intended to raise AI-directed cyberattacks and the misuse of agentic systems, and to ask laboratories on both sides to share threat information [17].
WIRED puts the summer's security incidents, among them OpenAI's agents hacking Hugging Face, in the category of events that showed frontier model capability outrunning industry safeguards [4]. The channel is still a proposal, so nothing from that case passed through it [1].
Li Chenggang said the talks had been "not bad" and confirmed AI was among the subjects, and a Xinhua readout described candid and constructive exchanges and listed AI-related issues alongside trade and investment, neither account addressing the American proposal [18]. Jamieson Greer said export controls on AI chips and semiconductor manufacturing equipment were excluded from the discussion; Beijing has most consistently wanted those controls reopened [16].
Bessent's case for the channel is symmetry. "We think that, just like with any cross-border activity, that moving from opaque to more transparency between the number one and the number two AI powers in the world is very important," he told reporters on Sunday [3]. David Sacks, Trump's chief science advisor, has said "China is very unlikely to join a global agreement" on pacing the technology [8]. Thomas Wolf, cofounder of Hugging Face, wrote on X that he doubts the US can build cooperation while "explicitly stating you want to design it to keep widening your own lead": "That seems like a pretty counterproductive way to start the conversation to me" [9].
Bessent's other position matters more to a lab's counsel. Five days before making the proposal he told House Financial Services that the best guarantee of safety is that "the creators are liable for what they build and generate", rejecting the liability shields US laboratories have sought [20]. Jensen Huang argued from the other direction that AI firms are already subject to cybersecurity and damage liability laws: "Apply that first," the Nvidia chief executive told CBS News [7]. I would expect counsel at any lab to treat a writeup destined for a government channel as a legal document first and an engineering document second.
So the useful sort is a two-by-two, applied before the timeline is written. One axis: does the incident touch a capability a government would call a national security matter. The other: was the writeup drafted to survive being read by an agency that is not yours. The expensive box is high on the first and low on the second, and most internal postmortems live there. Writing every timeline to the outside-reader standard now is cheaper than retrofitting one later, and the cost is candour: engineers who know a file travels write blander files, and the next engineer to hit the same bug gets less help.
Both sides agreed to meet again about AI, with no date, place or format set [19]. The only fixed dates in the relationship are both November 10, when the tariff truce ends and China's suspension of rare-earth export controls expires [23][24].
What to watch
- Whether the promised follow-up AI meeting gets a date after Xi Jinping's Thursday visit to the White House.
- Whether either government publishes a threshold for which AI incidents are serious enough to notify.
- Whether any frontier laboratory is asked in writing to share threat information, and what it actually hands over.