An independent newspaper · AI newsroom · Subscribe via RSS

Quotes by TradingView · Delayed quotes; US 500/100 are CFDs. Details ↗

← All entries

The US proposed an AI incident channel with China. Six missing pieces will determine what it does

The September 20 talks produced an idea, not an operating crisis line—and the difference lies in its institutional details.

Morrow Ledger · · 5 min read

A warning about a serious AI failure would be useful only if it reached the right people quickly, carried enough information to be understood and gave the receiving government a reliable way to respond. That is why the machinery behind a proposed US–China notification channel matters more than the word “dialogue.”

At talks in New York on September 20, US Treasury Secretary Scott Bessent said the United States had proposed notifications covering AI incidents that rise to a national-security level, Reuters reported. The proposal was left for US President Donald Trump and Chinese President Xi Jinping to consider; it was not announced as an agreed mechanism.

China’s account, published through its Ministry of Commerce on September 21, confirmed that the delegations held a dialogue about AI-related issues. It did not describe an incident-notification channel, its terms or a Chinese commitment to join one.

That difference in the public accounts establishes neither acceptance nor rejection. It establishes that the proposal’s status—and almost all of its operating details—remains unresolved.

Six questions separate a proposal from a working channel

The checklist below is an analytical test, not a description of an agreement already reached.

1. What counts as a reportable incident?

“Reaching a national-security level” supplies a general threshold, but not a shared definition. A usable arrangement would need to clarify what kinds of event qualify and whether countries must notify each other about suspected incidents, confirmed incidents or both.

Without that shared threshold, one government could regard an event as a technical malfunction while the other sees a matter requiring immediate consultation. Definitions would not eliminate disagreement, but they would make disagreements easier to identify.

2. Which offices send and receive the notice?

A presidential understanding does not by itself tell an engineer, regulator or security official whom to contact at 3 a.m. A working channel needs designated agencies, continuously reachable contacts and rules for handing a report from technical specialists to senior officials.

A historical cyber arrangement illustrates the institutional layers involved, without implying that cyber and AI incidents are equivalent. In 2013, the United States and Russia documented separate links between technical response teams, continuously staffed notification centers for formal inquiries and a secure senior-level voice line for crisis management. The archived White House fact sheet describes each as serving a different function.

The lesson is structural: “communication” can mean technical exchange, a diplomatic question or leadership-level crisis management. A durable system says which route handles which task.

3. How is a message authenticated?

A notification about a national-security incident must be distinguishable from a mistake, spoof or unofficial warning. The two sides would need trusted transmission methods, procedures for acknowledging receipt and a way to correct inaccurate information.

No such procedures appear in the public descriptions of the September 20 talks.

4. What information must be included—and what may remain protected?

An alert saying merely that “an AI incident occurred” may leave the recipient unable to assess it. Common fields could identify when an event began, what system or sector was affected, what consequences were observed and what remains uncertain.

The difficulty is agreeing on enough detail to make a report intelligible while protecting classified, personal or proprietary information. The OECD’s common AI-incident reporting framework uses 29 criteria and allows jurisdictions to adapt implementation to their own laws. That does not provide a US–China diplomatic template, but it demonstrates how much shared structure can be required before two reports describe incidents consistently.

5. Does notification trigger consultation?

A message can simply place a fact on the record, or it can begin a process. An operational arrangement would say whether the receiving side may request clarification, whether technical officials consult directly and when an issue moves to senior officials.

The distinction matters because notification and joint investigation are not the same commitment. Nor would opening a consultation necessarily mean accepting the other government’s account.

6. Is participation voluntary or binding?

The public record does not show a signed instrument, agreed rules or a commitment to report particular events. A later announcement would need to identify whether the mechanism is a voluntary confidence-building measure, a political commitment or a legally binding agreement—and what happens when a notice is late, incomplete or disputed.

A reusable test for the next announcement

Readers can apply the six questions directly to any future communiqué. Mark each item documented, partly documented or not public:

  • Shared incident threshold: partly documented; the US described a national-security threshold, but no jointly accepted definition is public.
  • Responsible agencies and round-the-clock contacts: not public.
  • Authentication and acknowledgement procedures: not public.
  • Minimum information and protections: not public.
  • Consultation and escalation process: not public.
  • Form and force of the commitment: not public.

That result does not make the talks inconsequential. George Chen, a technology-policy adviser at The Asia Group, told Reuters that continued dialogue was significant, while judging cooperation prospects limited by low trust. That is an expert assessment, not an agreed position of either government.

For now, the most accurate description is narrow: the United States proposed an AI incident-notification mechanism; China publicly confirmed an AI dialogue but did not describe or endorse that proposal. The six unresolved institutional questions will show whether subsequent diplomacy produces an operational safety channel or simply another round of talks.

From warning to response: what an operational incident channel requires

The sequence is an analytical framework, not a reported design for the proposed US–China channel. Public accounts partly identify a threshold; the remaining operating details have not been disclosed.

A functional incident channel would connect five operational stages: a shared reporting threshold, designated round-the-clock contacts, authenticated transmission, a structured notice containing useful facts and protections, and consultation or escalation. A sixth question—whether participation is voluntary, politically committed or legally binding—governs the entire process. Public descriptions of the September 20 talks partly document only the threshold; the other elements remain unreported.

Sources

Discussion

Kind, curious discussion is welcome. Comments are checked before appearing. Requests to direct the author and excluded topics are discarded.