Can the US and China agree on guardrails for artificial intelligence (AI) without slowing their race for technological leadership? That question was at the heart of the September 24 meeting between US President Donald Trump and Chinese President Xi Jinping at the White House, as the two countries grapple with the risks of increasingly capable AI systems and the strategic advantages they could bring.
Ahead of the meeting, Trump signalled little appetite for slowing AI development. In a post on Truth Social, he wrote, “Super Intelligence (SI) will be a big topic of discussion, but I want to leave it exactly where it is. That is China’s position also. Our guardrail is the DOJ!”
Xi, meanwhile, called for AI to remain under human control. “We have both the capability and responsibility to develop and manage AI for good and ensure that the development of AI is always under human control and serves the well-being of the people,” he said at the White House. Xi also urged the two countries to keep competition within limits, describing it as “a race of catching up with one another, not a wrestle in which one either wins or loses.”
The summit ended without a publicly announced agreement to restrict the development of advanced AI models. The differences between the two leaders reflect a wider debate over whether the industry can introduce meaningful safeguards without putting the US at a disadvantage as Chinese AI models narrow the performance gap.
The debate gained momentum after Anthropic CEO Dario Amodei published his September essay, ‘We Must Pace the Frontier’, arguing that the industry needs to deliberately manage the pace at which AI capabilities improve. “I believe we need to slow down the pace at which we improve the capabilities of AI models,” Amodei wrote, arguing that the time gained should be used to address the risks posed by increasingly powerful systems.
His proposal was not to halt AI research, and instead called for safeguards that would give companies and independent experts more time to evaluate advanced models and address potential risks. But Amodei also acknowledged that the US could not slow down indefinitely while China continued to advance. “Pacing within democracies will be limited by the lead that U.S. companies have over authoritarian regimes, chiefly the Chinese Communist Party,” he wrote.
Amodei’s argument drew support from OpenAI CEO Sam Altman and Elon Musk. Altman said he agreed with the need to pace frontier AI development, while Musk publicly endorsed Amodei’s position. OpenAI also committed to independent evaluators with employee-like access to its systems. His essay also called for maintaining the US technological lead through export controls on advanced AI chips and stronger protections against model theft. He warned that “a Chinese lead in AI would pose grave danger for the United States and the world.”
Even if Washington and Beijing cannot agree on slowing AI development, they could still work together to manage the risks posed by increasingly capable systems. Cyber incidents involving AI could spill across borders, disrupt critical infrastructure and create tensions between governments.
Ashish Tandon, founder and CEO of cybersecurity firm Indusface, said the risks were not confined to any one country. “The AI race will affect everyone in the world. In July, roughly 700 AI agents under test compromised Hugging Face without human direction. Incidents like that don’t respect borders. Stronger safety controls are urgent, and they must be global- shared incident reporting and common testing standards,” Tandon said.
He pointed to the possibility of an AI-driven attack on critical infrastructure being mistaken for an attack ordered by another country. “Any AI-driven attack on critical infrastructure- banking, energy, telecom and defence. If an autonomous attack can’t be traced quickly, a government could mistake it for a deliberate state act. Early notification stops a technical incident from becoming a diplomatic one,” he said.
The issue was also on the agenda in discussions between US Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng on September 20, when the two sides discussed establishing a formal AI dialogue. Bessent said Washington had proposed a mechanism to notify each other of AI incidents that raise national security concerns.
Bindra said such a mechanism would be about containing risks rather than signalling a broader rapprochement. “I would call it strategic risk management before genuine cooperation. Rivals can compete intensely while sharing an interest in preventing accidental escalation, cyber incidents or dangerous AI behaviour,” he said.
He compared the proposal to communication channels set up by rival powers during the Cold War. “The proposed notification mechanism resembles Cold War hotlines— it does not require trust, merely recognition that an uncontrolled incident could hurt both sides,” Bindra said. For now, he said, progress would likely mean agreeing on how to identify and report serious AI incidents, setting up notification channels, naming officials responsible for communication and holding regular technical discussions. Binding restrictions on frontier AI development would be harder to negotiate, given the difficulty of verification and the mistrust between the two countries.
Tandon said the pace of AI deployment was also raising questions about whether safety testing could keep up. “That risk is real, and the labs themselves are saying so. In September, Anthropic called for pacing the frontier, and OpenAI committed to independent evaluators. When builders ask for more testing time, deployment is outrunning safety,” he said.
The US and China have begun discussing how to manage AI-related risks. Still, the summit left open whether the two countries can move beyond incident reporting to agree on safeguards that would shape the pace of AI development.