Artificial intelligence security is entering the high-level agenda of China and the United States from the tech circles.U.S. Treasury Secretary Bessent and Chinese State Department Deputy Prime Minister Ho Chi Minh in the New York consultation before Xi Jinping's visit to the United States, plans to discuss AI security, open weight model and prevent abuse "barrier"; when Xi Jinping and Trump meet in Washington next week, AI governance was also included in the possible topics discussed.

The real difficulty is not whether the two countries recognize the risk, but who defines the risk, who is responsible for verifying security, and who is responsible after an accident. The Associated Press said this week that both sides were concerned that advanced models were abused or out of control, but at the same time suspected that each other would use "security" to maintain technological advantages or expand political control. Global governance is therefore facing a paradox: the two countries with the most ability to influence AI rules, and one of the two countries with the most lack of trust in each other.

原始来源 · apnews.comAP:中美AI安全合作为何陷入互不信任apnews.com ↗

“Safety” is no longer the same word.

The current U.S. AI security debate mainly revolves around how the work is divided between cutting-edge model developers, third-party assessments and government regulation. Reuters reports that Sam Altman, CEO of OpenAI, advocates the introduction of an independent supervision mechanism similar to that of the aviation industry; Dario Amodei, CEO of Anthropic, supports the gradual formation of stronger industry and international security standards; and Yuan Yuan, CEO of Nvidia, and others worry that new laws will slow innovation. The Trump administration generally emphasizesining U.S. technology leadership and is cautious of broad federal regulation.

原始来源 · reuters.comReuters:谁来约束更强大的AIreuters.com ↗

China's path is more inclined to the government to formulate standards, enterprises to undertake compliance obligations and regulatory authorities to conduct security assessments. Public policy documents have in recent years incorporated generated AI, algorithm recommendations, data security and AI agents into the regulatory system. China is developing national standards for the security of AI intelligence bodies, and policy discussions have also begun to show risk concepts such as "run out of control", data dumping, algorithm manipulation and system vulnerabilities.

2026世界人工智能大会现场,人形机器人进行演示。|来源:广州日报新花城
2026世界人工智能大会现场,人形机器人进行演示。|来源:广州日报新花城
原始来源 · reuters.comReuters:华为徐直军谈中国AI与前沿安全风险reuters.com ↗

Large U.S. AI companies have strong internal security teams and third-party assessment ecosystems, but the unified regulatory framework at the government level is still controversial; China has more centralized administrative regulatory capabilities, but the outside world has doubts about whether independent assessment agencies can really play a supervisory role outside of enterprises and regulatory departments.

Open Weight Model Makes Chain of Responsibility More Difficult

The differences between China and the United States are prominent in the open weight model. Many head-to-head AI enterprises in China rapidly expand overseas adoption through open or lower cost models, while most of the most advanced business models in the United States still maintain strong closure. Open weight is beneficial for researchers, developers and small and medium-sized enterprises to use and modify models at low cost, but once the model is downloaded, re-trained and re-deployed, the original developer's ability to control downstream uses decreases.

This is also one of the reasons why the Bessent-Houston summit will include the open weight model on the agenda. Reuters reports that U.S. officials are looking to discuss how to implement a barrier set against high-risk capabilities, malicious uses and autonomous agency behavior without completely blocking the open ecosystem.

原始来源 · reuters.comReuters:中美经贸磋商将讨论AI安全和开放权重模型reuters.com ↗
2026世界人工智能大会现场的机器人作业展示。|来源:新浪财经
2026世界人工智能大会现场的机器人作业展示。|来源:新浪财经

The problem is that the simple requirement of “corporate responsibility” does not cover the entire chain of responsibility. A basic model can be trained by A company, hosted by B platform, accessed by C developer to the agency system and then deployed through D enterprise to medical, financial, industrial or public service scenes.

AI agents turn “model error” into “system action”

The reason for the warming of security debates in 2026 is that AI agents quickly enter the real business. Unlike chatbots that only generate text, proxy systems can call software, browse the web, write code, operate databases and even execute transactions. Once the system has continuous permission, errors can expand from a single error response to continuous action.

China’s regulatory documents have begun to require AI agents to have the ability to detect, interfere, block and recover, and emphasize that when it comes to independent decision-making, users should be informed, retaining final man-control. U.S. technology companies have to explore similar issues through internal red line, power isolation, external evaluation and “stop switching”.

What really matters is not who believes who, but who accepts verification.

China-US AI competition will not disappear in the short term because of a summit. chip export control, model access restriction, talent competition and national security review will continue to affect both policies.

A more operational space for cooperation is the establishment of a minimum and verifiable common mechanism, for example, by adopting a compatible reporting classification for serious AI security incidents, keeping auditable operational records for high-risk agents, allowing certified third parties to use a joint test set to evaluate capabilities and abuses, and establishing emergency notification channels between governments when models face cross-border cyber attacks, biosecurity or critical infrastructure risks.

Instead, if “security” becomes just another political language that restricts each other’s chips, models and market access, while domestic companies and regulators do not need to undergo the same rigorous verification, so-called global AI governance will be difficult to build credibility. Whether it’s corporate self-discipline, government licenses or national standards, ultimately it should fall into the same question: when there is a major risk, who knows what’s going on, who has the right to immediately stop the system, who saves evidence, and who bears legal responsibility.

Xi Jinping and Trump talks may not be able to form a complete set of China-US AI security agreement, but if the two sides can advance the discussion from the abstract "leading" and "threat" to accident reporting, agency authority, model assessment and emergency contact these specific mechanisms, at least can set some verifiable boundaries for the competition.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.