US and China Open AI Safety Talks in New York
US-China AI safety talks opened in New York on September 20, putting model guardrails on the same negotiating table as tariffs and critical-mineral supplies. Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng began the meeting days before presidents Donald Trump and Xi Jinping are due to meet in Washington.
The talks mark a concrete diplomatic step after weeks of planning for a bilateral discussion on advanced AI risks. Officials have not announced an agreement, and the meeting also carries a crowded economic agenda that could limit how far the technology discussion advances.
The New York agenda joins four connected issues:
- Guardrails for increasingly capable AI models
- Security risks involving open-weight systems
- Chinese rare-earth and critical-mineral flows
- A trade truce expiring on November 10
US-China AI Safety Talks Move From Planning to Negotiation
Bessent and He met at JPMorgan Chase's Manhattan headquarters, with US Trade Representative Jamieson Greer also participating. Reuters reported that the session was expected to run through the day and help prepare potential deliverables for the Trump-Xi summit.
Before entering the meeting, Bessent said he expected focused and constructive discussions. The public comments did not define a proposed AI accord, technical standard or enforcement process, so the significance lies in the start of direct negotiations rather than a finished policy.
Earlier reporting indicated that officials were considering ways for major laboratories in both countries to monitor dangerous model behavior and exchange information about serious incidents. Cyberattacks directed by AI agents, recursive improvement and systems capable of helping with biological or nuclear threats were among the risks under discussion.
Model Guardrails Meet Open-Weight Competition
Any bilateral framework must bridge sharply different strategic incentives. The United States hosts most frontier-model developers, while Chinese laboratories have gained attention with cheaper and increasingly capable open-weight systems that developers can download, modify and deploy beyond the provider's direct control.
Washington has security concerns about how those models could be used or altered, yet broad restrictions would affect researchers and companies that depend on accessible weights. Beijing, meanwhile, can view US safety demands as an attempt to slow Chinese competitors while American companies preserve their lead.
The countries have nevertheless shown limited common ground. Both supported the Carolina Principles, a light-touch approach discouraging new AI-specific regulators and emphasizing existing legal frameworks. That alignment does not settle how either government would handle a severe cross-border incident or verify that laboratories follow voluntary safeguards.
Related Coverage
Rare-Earth Supplies Raise the Stakes for AI Infrastructure
The AI discussion is inseparable from the hardware supply chain. Chinese rare-earth magnets and other critical materials are essential inputs for electronics, energy systems and advanced manufacturing. US officials say current flows remain insufficient, making supply access a central issue in the same meeting.
That overlap gives both sides bargaining power but also creates risk. A technology-safety arrangement could become linked to tariff relief or mineral commitments, while a breakdown in trade negotiations could spill into cooperation on model oversight.
The trade truce expires on November 10. Negotiators are also examining possible reductions in tariffs on non-strategic goods, additional Chinese purchases of US products and continued controls aimed at industrial overcapacity and forced-labor concerns. None of those measures had been finalized when the talks began.
The Trump-Xi Summit Sets the Next Deadline
The September 24 summit gives negotiators only a short window to convert the New York discussions into a document or leader-level commitment. A narrow agreement could establish regular contacts, incident-notification channels or technical working groups without resolving the larger dispute over chips, models and export controls.
Verification will be the hardest part of any meaningful AI safeguard. Governments would need shared definitions for a serious incident, rules for protecting commercial and national-security information, and evidence that laboratories can detect behavior occurring inside complex agent systems.
A diplomatic channel can still reduce risk even without binding limits. Officials can clarify which model uses each side considers unacceptable, identify escalation paths after an AI-enabled cyberattack and keep technical disagreements from being interpreted immediately as hostile state action.
The next test is whether the summit produces a specific mechanism rather than a broad statement of concern. Dates for follow-up meetings, named agencies, reporting thresholds and a defined scope for laboratory participation would show that the negotiations have moved beyond political signaling.