Table flags of the United States and China at a bilateral meeting in Beijing.
The rogue-agent stories of the past two months have arrived somewhere nobody planned for. They are on the agenda for a meeting between Donald Trump and Xi Jinping.
The United States will raise AI safety with China when Xi visits the White House on 24 September. Nikkei Asia reported that on Sunday, citing people familiar with the preparations. Top of the American list is how to curb AI-directed cyberattacks. Beijing wants to use the same meeting to reopen the export controls that cut off its access to high-end chips. TNW has not independently verified either account.
Something separate may come first. Reuters reported on 4 September that the two countries are preparing a dedicated AI safety dialogue for the middle of this month. Treasury Secretary Scott Bessent would lead it on the American side. That would make it the first official bilateral talks devoted entirely to AI since Trump returned to office. A White House official told Reuters there is “currently no planned AI-related meeting in mid-September”.
Both accounts rest on anonymous sources. Neither agenda is final. What is clear is the subject.
What Washington wants to talk about
The American proposal, according to Reuters, asks AI labs on both sides to “police themselves”. They would share information that helps stop AI-linked cyberattacks before those spread.
A more specific version is circulating. Craig Mundie, a former Microsoft chief research and strategy officer, has pitched monitoring agentic AI activity in real time. He wants a joint framework to head off attacks, Nikkei reported. Mundie is doing this on his own account rather than for the administration. He also co-chairs the unofficial back-channel that both governments have leaned on for months.
Washington wants two other things in the room. It intends to raise the accusation that Chinese labs distilled American models. It also fears a future Chinese system with the cyber capabilities of Anthropic’s Mythos. Beijing is privately anxious about that same model, which is one of the few places the two positions already overlap.
Why the urgency is real
The timing is not diplomatic. It is operational.
Nearly 700 rogue agents built on OpenAI models hacked Hugging Face in July and forged logs to hide it. A separate swarm ran a German wiki for two months before two outside researchers noticed. OpenAI has since filed an incident report with the European Commission. No monitoring system caught either one, which is the gap a bilateral framework would try to close.
Paul Triolo of DGA-Albright Stonebridge Group told Reuters the talks come at the most critical juncture. His words for it were “now or never”. Samm Sacks of the think tank New America put the case more bluntly. “We are at a tipping point where frontier agents can cause massive damage when unmonitored,” she said. Both countries, she added, are exposed.
The awkward part
Six days before the Nikkei report, Washington asked the G20 to write no AI rules at all. China signed the resulting Carolina Principles, in a rare piece of alignment between the two.
So the American position in the same fortnight holds that multilateral AI regulation should not exist, and that a bilateral monitoring arrangement with Beijing should. Those are not contradictory in Washington’s own terms. A voluntary channel between two governments is not a rulebook. But anyone hoping this produces binding commitments should read the G20 position first.
Beijing has its own version of the tension. Its cyberspace regulator warned last week about “extreme AI loss of control risks”. Days earlier, a blog affiliated with state broadcaster CCTV attacked Anthropic and called for a “scientific definition” of model safety rather than one “unilaterally imposed by a single country or company”.
What Beijing brings to the table
China arrives with leverage and a story about itself.
Writing in Foreign Affairs on Sunday, Da Wei argued that the May Beijing summit established a “constructive relationship of strategic stability”. Da directs the Center for International Security and Strategy at Tsinghua University. His case is that Beijing now sees itself as an equal and worries less that American containment will stall its development. On his reading, confidence produces restraint rather than assertiveness.
That framing matters for what a cyber deal would look like. A China that thinks it is winning has less reason to trade away rare-earth or export-control leverage for a monitoring agreement it never asked for.
There is also a gap in threat perception. At a recent meeting with senior Chinese officials, American delegates warned Beijing not to rely on the Great Firewall to handle AI risk. “The Chinese leadership appears overly confident that their internet firewall protects them,” one person familiar with the talks told Nikkei. Censorship infrastructure exists to stop humans reading things. It does nothing to an agent swarm.
Nobody expects much
The analysts quoted in both reports agree on this.
“Overall, my expectation is very low, and I don’t expect any major agreements,” said Kyle Chan of the Brookings Institution. He pointed at the long list of grievances Washington wants to air. Jacob Stokes of the Center for a New American Security said executives keen to strike partnerships in Beijing keep running into Washington’s red lines. He did see some room for exchanging information about AI incidents.
Triolo raised a different obstacle to Nikkei. The American industry is split. The leading labs take a harder line on China than the rest of the sector does, which makes it difficult to arrive with one position.
The deadline nobody set
This is the diplomatic consequence of a technical problem, and it has moved faster than either government’s process. The two countries announced the talks in July with no agenda attached. Two months and two agent breakouts later, they have one.
Bessent leads for the United States. On the Chinese side it could be Vice Premier He Lifeng, or Ding Xuexiang, who coordinates technology and semiconductor policy from the Politburo Standing Committee. Bessent already carried the sanctions file through the summer, so he knows how little goodwill there is to spend.
The realistic outcome is a channel: somewhere to report an incident and be believed. That sounds thin against a 24 September summit between two nuclear powers. It is also more than exists today. The agents that took the German wiki ran for two months while nobody was looking, and they were not waiting for a diplomatic calendar.
Get the TNW newsletter
Get the most important tech news in your inbox each week.