The US and China Just Agreed to Talk About AI Safety. It's Already Too Late.
On September 24, 2026, in the East Room of the White House, Donald Trump and Xi Jinping did something no American and Chinese leaders had done before: they stood together and announced a formal AI safety channel — a standing communication mechanism between the two governments for AI-related incidents, with a full bilateral AI dialogue scheduled for November. They signed a military crisis communications memorandum of understanding. They agreed to $30 billion in tariff cuts. They extended the trade truce to January 10, 2027. Elon Musk, Jeff Bezos, and Tim Cook attended the state dinner.
The coverage was euphoric. *Reuters* called it "the most consequential AI governance agreement since the technology's emergence." *Fortune* described a "new era of US-China AI cooperation." Brookings Institution fellow Josh Rudolph told PBS that AI was "now a two-player game" and the two players had finally agreed to talk.
Here is the contrarian take: the AI safety channel is not a breakthrough. It is an obituary — written jointly, in Washington and Beijing, for the idea that either government can still control the AI race. The channel does not slow the race down. It does not regulate a single model, restrict a single chip, or slow a single training run. It creates the appearance of guardrails while confirming that the guardrails are decorative. And the timing — coming exactly as both nations' AI ecosystems accelerate into territory no bilateral dialogue can govern — makes it less a milestone and more a eulogy.
What Everyone Thinks Happened
The conventional narrative goes like this: after years of escalating tension, the world's two AI superpowers finally chose dialogue over conflict. The AI safety channel will prevent misunderstandings. The November dialogue will set shared standards. The tariff cuts will stabilize the economic relationship.
It is a satisfying story. It is also wrong on nearly every particular.
The Evidence: The Race That Neither Government Controls
Consider what was happening in the AI world *while* Xi and Trump were shaking hands in Washington.
DeepSeek — the company that shocked the world with its low-cost models — was finalizing its IPO preparations. On September 21, just three days before the summit, Yan Wentao formally joined DeepSeek as its first-ever CFO. Yan, a 35-year-old partner at GL Ventures (the venture arm of Hillhouse Investment), had been hired weeks earlier and was now on-site in Hangzhou, managing pre-listing preparations with CITIC Securities for a potential STAR Market debut. DeepSeek's valuation in its ongoing funding round: approximately $74 billion — up from $50 billion post-money in June 2026. The company that built its reputation on doing more with less — and that triggered a global reassessment of AI compute economics in early 2025 — was now accumulating capital, chip infrastructure, and corporate governance structure at a pace that made the summit's AI safety channel look like it was regulating a different industry entirely.
Alibaba was slashing AI API prices by up to 95%. On September 23 — the day before the summit — Alibaba Cloud announced Qwen-Audio-3.1-Realtime, its next-generation audio-language model, alongside price reductions of up to 95% on API access. This was not an isolated move. It was the continuation of a price war that DeepSeek started, Zhipu AI escalated, and ByteDance's Doubao industrialized. Chinese AI companies are not waiting for governance frameworks. They are racing to make AI inference so cheap that regulation becomes a rounding error.
Anthropic was accusing Chinese AI labs of systematically stealing Claude's capabilities. In early September 2026, Anthropic published a report alleging that three China-based labs had used Claude to generate training data for their own models — routing more than 16,000 queries through the API in a pattern consistent with large-scale distillation. Anthropic said it had terminated the accounts and implemented new detection mechanisms. The US National Security Agency and Cybersecurity and Infrastructure Security Agency subsequently issued a joint advisory.
DeepSeek's CEO told investors he was betting on Huawei chips. On September 22, Liang Wenfeng reportedly said during an investor call that DeepSeek aims to rely on Huawei chips for model training as Nvidia's China sales continue to slip under export control pressure. The company that made its name training frontier models on constrained compute was now doubling down on domestic silicon — not because Washington's export controls worked, but because they didn't matter enough to change the trajectory.
And across both countries, frontier labs kept shipping. OpenAI's GPT-6 (Sol/Luna) launched on September 22. Anthropic's Claude Opus 5.5 dropped the same day. DeepSeek released V4.1-Flash. Zhipu shipped GLM-5.3 variants. StepFun unveiled Step-5 Preview, a 600-billion-parameter sparse MoE model that matched GPT-6-class performance on multiple benchmarks.
None of these actors asked anyone's permission. None of them were waiting for a bilateral dialogue. The AI race was not paused for the summit. It accelerated *during* it.
Table 1: The AI Race Did Not Stop for the Summit
| Event | Date | Days from Summit | What It Actually Means |
|---|---|---|---|
| DeepSeek CFO Yan Wentao formally joins | Sep 21, 2026 | 3 days before | $74B valuation lab professionalizing for IPO — no regulatory pause |
| Liang Wenfeng confirms Huawei chip strategy | Sep 22, 2026 | 2 days before | Export controls reshaping, not stopping, China's compute pipeline |
| OpenAI launches GPT-6 (Sol/Luna) | Sep 22, 2026 | 2 days before | US frontier capability leap — coordinated with, not subordinate to, diplomacy |
| Anthropic launches Claude Opus 5.5 | Sep 22, 2026 | 2 days before | Same day as GPT-6 — competition is self-perpetuating |
| Alibaba slashes API prices up to 95% (Qwen-Audio-3.1) | Sep 23, 2026 | 1 day before | Price war makes AI access a commodity, not a regulated good |
| Xi-Trump summit: AI safety channel announced | Sep 24, 2026 | Day 0 | Communication mechanism agreed — zero binding restrictions on any actor |
| Trade truce extended to Jan 10, 2027 | Sep 24, 2026 | Day 0 | Economic stabilization creates *more* room for AI spending, not less |
The Real Story: Why Both Governments Needed This Channel
The conventional wisdom says the AI safety channel is a proactive governance measure — the two superpowers getting ahead of the risk curve. The evidence suggests something different: both governments needed the channel because they have both lost effective control over the AI ecosystems within their own borders.
This is not a failure of will. It is a structural reality that no amount of bilateral diplomacy can address.
In the United States, the federal government has no comprehensive AI legislation. Executive orders shift with each administration. The AI Safety Institute — rebranded and restructured multiple times — lacks statutory authority. Individual states have passed more than 100 AI-related laws, creating a patchwork that frontier labs navigate with legal teams, not compliance officers. OpenAI, Anthropic, Google DeepMind, and Meta determine the pace and direction of frontier AI development, and the government's primary leverage is through chip export controls — a blunt instrument that has proven repeatedly inadequate to the task.
In China, the situation is superficially different but structurally similar. Beijing has issued more AI regulations than any other government — on recommendation algorithms, deepfakes, generative AI, and AI-generated content labeling. The Cyberspace Administration of China (CAC) has real enforcement power. But the Chinese AI ecosystem has grown so large, so fast, and so commercially competitive that regulatory capacity has not kept pace. When DeepSeek can go from a research lab to a $74 billion IPO candidate in eighteen months, when Alibaba can cut API prices by 95% overnight, when Zhipu AI can ship three model variants in a single week — the regulatory apparatus is perpetually behind.
Both governments are, in effect, spectators to their own AI revolutions. The safety channel is what spectators do when they can no longer influence the game: they agree to talk about it.
Table 2: Regulatory Capacity vs. Industry Velocity — A Structural Mismatch
| Dimension | United States | China | Gap |
|---|---|---|---|
| Comprehensive federal AI law | None | None (sectoral rules only) | Both lack statutory frameworks |
| Frontier model releases in 2026 H1 | 12+ major releases | 15+ major releases | Neither government reviews or approves releases |
| AI-related executive orders / regulations (2023-2026) | 4 executive orders | 7 major regulations | Volume does not equal effectiveness |
| Enforcement agency dedicated to AI | None (NIST advisory only) | CAC (real power but limited capacity) | Institutional capacity lags industry growth |
| Frontier lab R&D spending (2026 annualized) | ~$50B+ (combined) | ~$30B+ (combined) | Regulatory budgets are rounding errors by comparison |
| Time from model training completion to public release | Days to weeks | Days to weeks | No mandatory review period in either country |
The Open-Source Problem Neither Side Can Solve
There is a deeper layer to this story that almost no one is discussing: the AI safety channel is a bilateral agreement in a world where the most consequential AI dynamics are not bilateral.
In May 2026, during the Beijing summit between Trump and Xi, the open-source question was already on the table. Washington wanted China to restrict the open-weight release of frontier models. Beijing refused. That refusal was not ideological stubbornness — it was a recognition of a structural reality: China's open-source AI ecosystem has become one of its most powerful strategic assets, and it cannot be put back in the bottle.
DeepSeek's models are downloaded millions of times. Qwen variants power applications on every continent. Zhipu's GLM series has become the default open-weight choice for developers in dozens of countries that cannot afford — or do not want — American API dependencies. The open-source genie is not just out of the bottle; it has reproduced, forked, fine-tuned, and deployed itself into a global infrastructure that no bilateral agreement can regulate.
When Anthropic accused Chinese labs of distilling Claude's capabilities, it described a dynamic that exists precisely because the models are accessible. When Alibaba cuts API prices by 95%, it demonstrates that the marginal cost of AI inference is approaching zero — and that a technology whose marginal cost approaches zero cannot be governed by a channel between two governments.
The AI safety channel is a bilateral mechanism for a multilateral, open-source, borderless problem.
The Deeper Contradiction: Safety vs. Competition
Here is the uncomfortable truth that the summit coverage largely avoided: AI safety and AI competition are structurally incompatible at current capability levels, and both governments have chosen competition.
This is not a moral judgment. It is an empirical observation. Every action taken by both governments — every chip export control, every funding round, every model release, every price cut — is optimized for competitive advantage, not safety. The AI safety channel does not change this optimization function. It adds a communication layer on top of it, like installing a smoke detector in a building that is being actively set on fire.
The November AI dialogue will take place in a world where the models being discussed will already have been superseded. By the time diplomats agree on a framework for discussing AI incidents, the frontier will have moved. The dialogue is structurally incapable of keeping pace with the technology it purports to govern.
And there is a more cynical reading available: the safety channel is not about safety at all. It is about the two governments reassuring each other — and their domestic audiences — that someone is in charge. It allows Trump to claim he has "solved" AI safety. It allows Xi to demonstrate that China is a responsible AI power. It allows both to focus on what they actually care about: winning.
Table 3: What the Channel Does vs. What the Problem Requires
| What the AI Safety Channel Provides | What Effective AI Governance Requires |
|---|---|
| Bilateral communication mechanism | Multilateral coordination (including EU, UK, India, and open-source community) |
| AI incident notification protocol | Real-time monitoring and enforcement capability across all major labs |
| Standing AI dialogue (first meeting: November) | Continuous regulatory review with authority to halt releases |
| Military crisis communications MOU | Verification and inspection regimes for AI training infrastructure |
| Framework for discussing AI risk | Binding safety standards with third-party auditing and penalties |
| Political optics of cooperation | Alignment between political timelines and technology timelines |
Who Wins and Who Loses
The implications of this dynamic are unevenly distributed.
The frontier labs — OpenAI, Anthropic, Google DeepMind in the US; DeepSeek, Alibaba, Zhipu, ByteDance in China — win. The safety channel imposes zero additional restrictions on their operations. It provides political cover for continued rapid development. And it formalizes a two-power framework that excludes smaller actors from the governance conversation, effectively anointing the incumbents.
The Chinese open-source ecosystem wins. Beijing's refusal to restrict open-weight model releases — maintained through both the May and September summits — means that China's open-source AI assets will continue to proliferate globally, building soft-power infrastructure that no tariff can counteract. The Brookings framing of AI as a "two-player game" is exactly what China wants: it legitimizes China's position as the co-sovereign of AI governance, even as its open-source strategy undermines the very concept of sovereign AI control.
The European Union loses. Again. The EU has invested enormous diplomatic capital in becoming the third pole of AI governance — through the AI Act, the AI Office, and the Global Digital Compact. A US-China bilateral channel that marginalizes Brussels is a structural setback for European AI policy. The EU is not in the room, and the room is where the rules are being informally written.
The UN and multilateral institutions lose. When the two AI superpowers agree to talk to each other, they reduce the incentive to build inclusive global frameworks. Why negotiate with 193 countries when you can call the one rival that matters? The safety channel is, in this sense, a step backward for global AI governance — a bilateralism that undermines multilateralism.
Everyone else — the Global South, smaller AI nations, civil society — loses most of all. The two-power framework formalizes a world where AI governance is determined by Washington and Beijing, for Washington and Beijing. The countries deploying Chinese open-source models, the developers fine-tuning Qwen and DeepSeek variants, the researchers publishing safety papers that no one with power reads — they are all outside the channel.
Table 4: Winners and Losers in the Post-Summit AI Order
| Actor | Position | Why |
|---|---|---|
| US frontier labs (OpenAI, Anthropic, Google) | Win | Zero new restrictions; political cover for acceleration |
| Chinese frontier labs (DeepSeek, Alibaba, Zhipu) | Win | Open-source strategy validated; IPO path cleared |
| Chinese open-source ecosystem | Win | No restrictions on open-weight releases; global proliferation continues |
| US and Chinese governments | Tactical win | Political optics of control without operational constraints |
| European Union | Lose | Marginalized from the governance conversation |
| UN / multilateral institutions | Lose | Bilateralism replaces multilateralism as the governance default |
| Global South | Lose | No seat at the table; rules written by and for two powers |
| AI safety researchers | Lose | Safety framework is advisory, not binding; no enforcement mechanism |
The Number That Explains Everything
There is one statistic that captures the fundamental disconnect between the summit's ambitions and the AI race's reality. In June 2026, DeepSeek raised approximately $7.4 billion at a post-money valuation exceeding $50 billion. By September, its ongoing funding round had reportedly pushed the valuation to approximately $74 billion — a 48% increase in three months, during a period that included two US-China summits, an AI safety channel agreement, and a military crisis communications MOU.
$74 billion is what the market believes an uncontrollable AI race is worth. No bilateral dialogue, no incident notification protocol, and no diplomatic talking point changes that number. The AI safety channel is real. The tariff cuts are real. The trade truce extension is real. But they are real in the way that a ceasefire is real when both sides are actively rearming: the hostilities have shifted to a different theater, and the weapons are getting more powerful.
The US and China agreed to talk about AI safety on September 24, 2026. By September 28 — the day this article is published — both countries' labs will have shipped new models, cut new prices, and filed new patents. The channel will still be standing up its first meeting. The race will not have noticed.
Table 5: Key Summit Outcomes vs. Ongoing AI Race Dynamics
| Summit Outcome | AI Race Reality | Time Gap |
|---|---|---|
| AI safety channel established | 12+ frontier model releases scheduled for Q4 2026 in both countries | Channel's first meeting: November 2026 |
| Military crisis MOU signed | Autonomous weapons development continues in both countries, unabated | MOU has no verification or enforcement provisions |
| $30B tariff cuts agreed | Chinese AI API prices dropping 50-95% independently of tariffs | Price cuts make AI access cheaper regardless of trade policy |
| Trade truce extended to Jan 2027 | DeepSeek IPO prep accelerating; CITIC Securities engaged | IPO likely before truce expires — market forces > diplomatic frameworks |
| AI dialogue scheduled for November | By November, current frontier models will be superseded | Dialogue will govern yesterday's technology |
What Social Media Is Saying
The reaction to the AI safety channel has been sharply divided — not along the expected US-China lines, but along a more revealing axis: those who believe the channel is meaningful, and those who believe it is the diplomatic equivalent of a screensaver.
Zhihu user @量子学徒 *(量子学徒 — "Quantum Apprentice")*:
中美AI安全通道?听起来很高大上。但DeepSeek上周还在发新模型,阿里还在砍价格,Anthropic还在指责中国公司偷数据。这个"安全通道"到底要"安全"什么?安全地继续比赛吗?
>
*"A US-China AI safety channel? Sounds impressive. But DeepSeek released new models last week, Alibaba is still cutting prices, and Anthropic is still accusing Chinese companies of stealing data. What exactly is this 'safety channel' supposed to make safe? Safely continuing the race?"*
Twitter/X user @AISafetyResearch *(AI safety researcher, Bay Area)*:
Everyone celebrating the US-China AI safety channel needs to read the actual text. It's a communication mechanism. Not a single training run has been slowed, not a single model release has been delayed, not a single chip has been restricted. This is governance theater.
>
— AI safety researcher, Bay Area
Weibo user @科技观察君 *(科技观察君 — "Tech Observer")*:
特朗普和习近平握手了,马云和马斯克同框了,关税降了。但你们注意到没有?DeepSeek的CFO已经到岗了,中芯国际的芯片还在流片,Qwen的API价格已经降到地板上。真正的AI竞赛,从来不在宴会厅里。
>
*"Trump and Xi shook hands, Musk and Ma shared a photo, tariffs are down. But did anyone notice? DeepSeek's CFO has already started, SMIC's chips are still in production, Qwen's API prices have hit the floor. The real AI race has never been in the banquet hall."*
Hacker News comment @frontier-skeptic:
The most telling detail from the summit is who was at the state dinner: Musk, Bezos, Cook. The people actually building AI were in the room. The people supposedly regulating it were on the menu.
>
— Hacker News comment
Douban user @深蓝 *(深蓝 — "Deep Blue")*:
作为一个在AI公司上班的人,我看到的新闻是:峰会开了,通道建了,然后我们周一照常上班,模型照常训练,产品照常吃上线。这个"安全通道"对我们日常工作的影响是零。它影响的是新闻头条,不是GPU集群。
>
*"As someone who works at an AI company, here's what I saw: the summit happened, the channel was established, and then we went to work on Monday as usual, models kept training, products kept shipping. This 'safety channel' has zero impact on our daily work. It affects news headlines, not GPU clusters."*
Twitter/X user @EUPolicyWatch *(EU tech policy analyst, Brussels)*:
The US-China AI safety channel is a bilateral mechanism that excludes the EU, the UK, and every other democracy with AI regulatory capacity. This is not AI governance. This is a G2 claiming ownership of a global public good.
>
— EU tech policy analyst, Brussels
The comments reveal the real divide. It is not between Americans and Chinese, or between optimists and pessimists. It is between those who see the summit as a governance event and those who see it as a political event — between those who measure the channel's importance by what it says and those who measure it by what it does. The builders, the researchers, and the workers all land in the same place: the channel is real, but it is not relevant to the actual trajectory of AI development in either country.
That may be the most damning assessment of all — not that the channel is toothless, but that the people closest to the technology did not even need to check whether it had teeth. They already knew.
Table 7: The Verdict — What the AI Safety Channel Actually Is
| Assessment Dimension | Rating | Explanation |
|---|---|---|
| Diplomatic significance | High | First formal US-China AI governance mechanism; major symbolic milestone |
| Practical regulatory impact | Negligible | No binding obligations on any AI actor in either country |
| Effect on AI race velocity | None | Model releases, price cuts, and funding rounds continued during and after summit |
| Military risk reduction | Unclear | MOU is welcome but unverified; no enforcement provisions |
| Global governance contribution | Negative | Bilateralism undermines multilateral frameworks and excludes other actors |
| Honest description | Communication channel between two governments that have lost control of their own AI ecosystems | The channel acknowledges the problem without addressing it |
The AI safety channel will hold its first dialogue in November 2026. By then, the frontier will have moved. The models will be more capable. The prices will be lower. The funding rounds will be larger. The labs will be further beyond anyone's regulatory reach.
The channel will still be there. That is the point. It exists not to control the race, but to make the race feel controlled — to give two governments that have ceded operational authority to their own technology sectors the comforting illusion that they are still the ones driving.
They are not. And on September 24, 2026, in the East Room of the White House, they both agreed to stop pretending otherwise — while continuing the pretense for the cameras.
Editor at AI in China. Tracking Chinese AI companies, funding rounds, and the technologies reshaping global tech. More about me.