The United States and China are the two countries building the world’s most advanced artificial intelligence systems. They are also rival superpowers, with both seeing AI as crucial to the battle for supremacy. Taken together, these dynamics are driving an ever-accelerating race to develop the most powerful – and potentially dangerous – AI systems first.
After the summit between US President Donald Trump and Chinese President Xi Jinping in Beijing, the two countries agreed to start an intergovernmental dialogue on the topic of AI. But can superpowers locked in the battle for AI supremacy also help reduce the risks of the technology they are competing over?
Yes, but it requires modest goals and a pragmatic approach. I call this approach “AI security in parallel.”
The US and China will not act in lockstep on AI security, and it is probably not possible to reach binding agreements with any real teeth for both sides at this time. But they can move forward on parallel paths, each advancing technology and also taking steps to reduce risks because they believe it is essential to their own national security – regardless of what the other does. In this process, the most consequential decisions are made within the two countries, not between them. And these domestic policy decisions are guided by the cold calculation of national (and political) self-interest.
But even within the realpolitik of great power competition in AI, the strategic engagement between the United States and China still plays a crucial role. The engagement can advance two important goals: improving the security of systems built in both countries and increasing mutual awareness of the security practices used (or not used) in the other country. The former reduces the risk of AI disasters that could spread across borders, while the latter can reduce some of the potentially dangerous racial dynamics. At a time when everyone is venturing into unchartered territory, it makes sense to maintain a level of connective tissue that increases visibility and promotes the safe development of technology in both places.
The troubling reality of AI today is that even the world’s leading AI scientists – be they in Silicon Valley, Shanghai or elsewhere – don’t know how to ensure the technology remains safe as it becomes more powerful. They’re desperately trying to figure it out, often competing with the rapidly evolving capabilities of the models they’re building. During this time, it is far less important that the United States and China agree to take the same steps on AI security than that both countries get better at actually building AI safely.
At the same time, AI security means creating contact points and information channels between the United States and China that strengthen the security capabilities of both sides. In practice, this could mean limited and strategic sharing of emerging threats and best practices for detecting and mitigating dangerous AI capabilities. These exchanges may occur as part of the upcoming U.S.-China intergovernmental dialogue and, for less sensitive areas of engagement, as part of nongovernmental Track II dialogues between the countries.
Both the US and China have experiences worth sharing with AI security and governance. AI technical research into border security has deep roots here in the United States, but is a relatively newer field in China. One of the most valuable things that could come from U.S.-China engagement in AI would be sharing approaches to testing dangerous new capabilities in models: the ability to detect novel pathogens or intentionally escape the control of a human operator.
Technical discussions along these lines are delicate but doable. In certain areas, there is a fine line between figuring out how to test a new skill and figuring out how to build that skill. The key is to tip this balance heavily in favor of safety-enhancing rather than capability-enhancing techniques. If there’s an intervention that makes a model 25 percent safer and 2 percent more powerful, that’s probably the kind of technology we’d expect even our adversaries to use. Close monitoring of this balance will be crucial to any discussions. If direct technical exchanges are deemed too risky, discussions can be deepened to focus on more comprehensive testing approaches.
And while the United States may currently be a leader in developing these tests and protections, that lead is far from guaranteed. Chinese AI researchers have proven to be incredibly inventive, despite having significantly less computing power due to US export controls. Future breakthroughs in AI testing and security could just as easily emerge from the Chinese ecosystem, and both the United States and China would benefit from their exchange.
Beyond technical research, China has extensive experience in the fundamental processes of regulating AI. Over the past four years, China has enacted the world’s most comprehensive and detailed regulations on AI, and has done so in a way that has not dramatically slowed innovation. Regulators have built a flexible and constantly evolving system of mandatory model registration and testing, combined with technical standards written by industry, academic and government experts. China’s early regulations focused on controlling the way AI creates and disseminates information online, ensuring the technology does not disrupt existing information controls. But in recent years, regulators have used these tools to create an end-to-end system for labeling AI-generated content, strict rules for companion chatbots, and new protections for agent AI.
The United States should not copy China’s regulatory approach. Many parts are in direct contradiction to America’s core values of free speech and the power of the state over private companies. But we can learn from aspects of the regulatory and technical infrastructure. Despite our drastically different political systems, China’s AI policy community has no problem learning from the United States and adopting good policy ideas. We should be ready to do the same.
Aside from this type of learning, AI security simultaneously crucially increases mutual awareness of what each side is doing in terms of governance and technical safeguards. It is unlikely that the United States and China will agree on binding reciprocal measures, but it is critical that we have some sense of the other side’s approach. With no information on testing or guardrails, leaders in both countries are understandably assuming the worst: that the other side will sacrifice all security measures in a reckless race to build the most powerful system. Structured dialogue is an important channel for explaining approaches and regulatory mechanisms that are often completely misunderstood from a distance.
This process is not based on trust or on the other side simply telling the truth or following through on their promises in good faith. At this point, trust between superpowers is both unrealistic and unnecessary. Instead, these conversations are intended to build trust. The other side doesn’t have that trust Intentionsbut rather in theirs Understanding: the technology, the risks and how to mitigate them.
When Chinese officials tell their American counterparts that they are taking a particular AI risk “very seriously” and are testing it, Americans cannot simply take their word for it. But in the course of a dialogue it often becomes completely clear whether the other side has seriously thought about this risk and made an effort to create the necessary guardrails. This is no guarantee that they will take action, but combined with a clear analysis of the other side’s interests, it is a powerful data source for modeling their possible actions. This kind of mutual awareness will be important as we navigate the coming years.
Crucially, a U.S.-China AI dialogue should not be viewed as a negotiating platform in which China offers more security measures in exchange for easing U.S. chip export controls. The security of advanced AI systems is a complex and constantly evolving problem. In order to make real progress here, a real and sustained will to tackle the problems is required. Making it a half-hearted concession to another country simply won’t work. If that’s all Chinese officials care about, we should walk away. But if they are interested in a serious exchange, we should be ready to engage.
Compared to some of the more ambitious international governance proposals – for example, an AI non-proliferation treaty – the goals of AI security are modest. It sees binding agreements between countries as a bonus rather than an immediate goal. Depending on how technology develops in the coming years, this could well prove insufficient. If that is the case, we must adapt quickly. But we have to start somewhere, and if we start with the mental safety model in parallel, we could build a more solid foundation and avoid the pitfalls that come with setting unrealistically high goals at the start.
Even if perfectly implemented, the parallel approach to AI security cannot guarantee that the United States and China will successfully manage the changes and threats the technology may bring. Given the enormous technical and geopolitical uncertainties, there is little possibility of offering this guarantee. As both the United States and China head toward this uncertain future, we have a better chance knowing that we are moving in the same direction.
https://carnegieendowment.org/emissary/2026/07/ai-safety-parallel-us-china
