Policy
US and China Agree on AI Emergency Protocol at Beijing Summit
The Trump-Xi summit produces the first bilateral AI safety framework, establishing a direct communication channel for AI incidents and a joint working group on frontier model risks.
By Michael C ·

The United States and China have agreed on a bilateral AI safety protocol, the first formal framework governing how the two countries will communicate and coordinate on artificial intelligence risks. The agreement, announced at the conclusion of the Trump-Xi summit in Beijing, establishes a direct communication channel for AI incidents, a joint technical working group on frontier model risks, and a shared commitment to notify the other party before deploying AI systems in sensitive domains.
What the Protocol Contains
The framework is deliberately narrow in scope. It does not address AI in military applications, does not impose restrictions on AI development or deployment, and does not create any enforcement mechanism. What it does create is a structured channel for communication: a dedicated hotline between AI safety officials at the US National AI Safety Institute and its Chinese counterpart, and a commitment to share information about AI incidents that could have cross-border implications.

The joint technical working group will focus specifically on frontier model risks: the scenarios in which highly capable AI systems could behave in unexpected or dangerous ways. This focus was driven in part by Anthropic's Mythos model, which demonstrated autonomous capabilities in February 2026 that alarmed safety researchers in both countries. The working group will meet quarterly and will share technical findings on model evaluation methodologies.
We have agreed that the risks posed by the most capable AI systems are not a competition between our countries. They are a shared challenge that requires shared attention.
US National Security Advisor, post-summit press briefing, Beijing, May 2026
The Road to Beijing
The agreement was months in the making. Informal discussions between US and Chinese AI safety officials began in late 2025, following a series of incidents in which AI systems deployed by companies in both countries exhibited unexpected behaviours in testing environments. The Mythos demonstration in February accelerated the timeline, with both governments concluding that the risks of non-communication outweighed the diplomatic costs of formal engagement.
The talks were complicated by the broader US-China relationship, which remains strained over trade, Taiwan, and technology export controls. The AI safety framework was deliberately separated from these issues and negotiated through a back-channel process that kept it insulated from the main diplomatic agenda. The decision to announce it at the summit was a signal from both sides that they wanted to give it political weight.
What It Does Not Do
Critics of the agreement have noted what it does not include. There is no provision for joint AI safety research, no mechanism for verifying compliance with the notification commitment, and no agreement on what constitutes an AI incident requiring notification. The framework is a statement of intent rather than a binding treaty, and its practical impact will depend entirely on the willingness of both governments to use the channels it creates.
The export control regime on advanced semiconductors remains in place, and the US has not indicated any intention to relax restrictions on Chinese access to the most advanced AI chips. The safety protocol and the technology competition exist in parallel, and there is no indication that progress on one will influence the other. For now, the agreement represents a floor of communication rather than a ceiling on competition.
The establishment of even a minimal communication channel between the world's two largest AI powers is a meaningful development. The history of nuclear arms control suggests that formal communication mechanisms, however limited, can prevent miscalculation and create the conditions for more substantive agreements over time. Whether the AI safety protocol follows that trajectory will depend on events that neither government can fully control.