By Jim Shimabukuro (assisted by Muse & Perplexity)
Editor
A truly successful summit would have left the world with signed duties, deadlines, tests, and records that people could examine.
The Washington summit of September 23–25, 2026 ended with modest progress on trade and a thin result on artificial intelligence. The White House said, “The two countries reached consensus on recommendations for more favorable tariff treatment for $30 billion of non-sensitive goods in each direction” (USA Today, 2026). On AI, the announced outcome went little further than process: “On artificial intelligence, the two sides agreed to hold a dialogue on the technology’s risks and benefits, with the next round of discussions set for November, and to set up a communication channel for AI-related incidents” (USA Today, 2026). No binding AI agreement emerged.
The leaders’ public language revealed a basic tension. Xi Jinping offered a broad principle, saying that AI development should “always remain under human control and serve the well-being of the people” (SFG Media, 2026). In his September 22 address to the U.N. General Assembly, Trump rejected international AI oversight: “The United States totally rejects any attempt to construct a globalist scheme of control” for artificial intelligence, which he said would henceforth be called “Super Intelligence” (White House, 2026).
After the summit, Trump emphasized terminology more than policy. “I say this that superintelligence, SI, I don’t call it AI anymore,” he told reporters, adding that “we had a big talk on SI, and he likes the idea of changing the name to SI, too” (USA Today, 2026). An ideal summit would have used their interest in control and national authority to settle three questions. The following agreements did not occur. They describe a plausible package that could have served both governments and reduced AI risks worldwide.
A hotline that actually works
The real summit’s communication channel was a useful starting point. Its value would be tested when a system behaved in a way that looked hostile. Security experts described the danger in concrete terms: an AI system could interfere with a nuclear command network or start a military cyber operation, leaving leaders little time to decide whether the event was an attack, an accident, or an unauthorized action (Reuters, 2026b). Tianjiao Jiang of Fudan University explained the purpose of rapid contact: “A hotline could allow one government to tell the other that an unusual AI operation was accidental, unauthorised or still under investigation before it was treated as deliberate state action.” (Reuters, 2026b).
A successful summit would have produced a signed AI Incident Communication Protocol, effective within thirty days, with clear stipulations. Each government names a civilian lead office and a military backup office. Both staff the secure line around the clock with officials authorized to acknowledge an alert immediately. The agreement defines the events that trigger contact: an autonomous cyber operation that crosses into the other country’s networks; unexpected AI activity affecting nuclear command, energy, finance, or health systems; evidence that a powerful model has been stolen; and a model failure that could spread across borders.
The hypothetical protocol sets deadlines. The receiving side acknowledges an alert within ten minutes. Within thirty minutes, it provides one of three signed responses: the activity was authorized; it was unauthorized or accidental; or the government was still investigating. That first response carries no admission of legal responsibility. It exists to slow escalation while officials establish the facts. Each message uses a standard bilingual form recording the time, affected system, known scope, steps taken to contain the event, and the time of the next update.
Technical reliability would be tested, not assumed. The two sides conduct an announced communications test every month and a surprise exercise every quarter. Once a year, they run a joint simulation involving an AI-driven cyber incident near critical infrastructure. Each government could protect classified details while still proving that alerts reached an empowered official and received an answer within the agreed deadline. A bilateral secretariat publishes quarterly figures on connection uptime, test completion, response times, and unresolved failures. It discloses no operational secrets.
This design would address a weakness already identified by specialists. Existing U.S.-China crisis communication has sometimes failed because officials did not answer quickly, and analysts have linked that delay to the approval structure inside the Chinese government (Reuters, 2026b). The ideal agreement gives preauthorized duty officers limited power to send factual acknowledgments before senior leaders settled on a full response. Washington accepts the same rule. The hotline then performs a defined emergency function instead of serving as a diplomatic symbol.
Humans decide on nuclear weapons
The strongest public point of agreement was human control. Xi used that phrase at the White House (SFG Media, 2026). Specialists from both countries had already translated it into a specific security rule. Melanie Sisson of the Brookings Institution argued that humans should “retain sole authority to initiate AI-enabled cyberattacks against the other country’s nuclear command, control and communications systems or strategically important infrastructure” (Reuters, 2026b). Jiang stated the same rule directly: “Decisions to launch cyberattacks on each other’s nuclear command, control and communications systems or critical infrastructure must be made only by humans, not AI.” (Reuters, 2026b).
The ideal summit would have turned those statements into a Joint Declaration on Human Authority over Strategic Systems. In this hypothetical process, Trump and Xi sign it personally. The declaration bars an AI system from authorizing or initiating the use of a nuclear weapon. It also bars an AI system from independently starting a cyberattack on the other country’s nuclear command, control, and communications systems. Energy, financial, and healthcare infrastructure receive parallel protection when an attack could cause mass casualties or create a strategic crisis.
The declaration would specify the operational meaning of human authority. AI could collect information, flag anomalies, estimate consequences, and present options. A named human official has to approve any covered action. A second authorized person confirms the decision. The command path preserves the identities of both people, the information presented to them, the action approved, and the exact time. No covered system could execute a machine-generated command by default or treat a human’s failure to respond as approval.
Verification must focus on procedures because neither government would permit foreign inspectors to examine its nuclear systems in detail. Each side establishes an internal review team with civilian and military members. Once a year, the team certifies that covered systems require two recorded human approvals. The two governments exchange summaries that describe the test method, the number of systems reviewed, and any corrective action, while withholding weapon design and targeting information. Reciprocal observers could watch controlled simulations showing that a machine-generated recommendation stops at the authorization gate.
The declaration would also connect to the incident hotline. If either side discovered that an AI system had crossed a protected boundary, it notifies the other side immediately, isolate the system, preserve relevant logs, and begin a joint factual review. A standing group of legal, military, and technical officials meet after every exercise or incident to correct ambiguous language. Violations trigger an emergency leaders’ call and suspension of the affected system pending investigation.
This arrangement could fit both leaders’ stated positions. Xi would gain a written application of his call for AI to remain under human control. Trump retains domestic enforcement and national decision-making. The agreement regulates a narrow class of actions with catastrophic potential. It leaves each country free to develop commercial and educational systems under its own laws.
Chips, models, and shared testing
The hardest bargain would concern the physical resources used to build advanced AI and the tests applied before powerful models reach the public. U.S. controls still cover advanced computing products destined for China, even after targeted relief. Reuters summarized the legal position: “China remains subject to strict controls under the advanced computing provisions of the EAR, although there have been targeted areas of relief.” (Reuters, 2026c). The same analysis described a gap created by cloud computing: “a Chinese company can sign up as an infrastructure as a service (IaaS) customer for a data center in Malaysia, which is not a restricted destination for controlled chips. In this hypothetical, the Chinese company can then train an AI model by remotely accessing the chips that it would not be permitted to receive in China without a BIS license.” (Reuters, 2026c).
A durable settlement would acknowledge two realities. Washington continues restricting the most capable chips and computing services when they could support military or intelligence work. Beijing seeks predictable access for civilian research and commerce. The ideal agreement creates three published categories: prohibited military end uses; licensed high-capability civilian use; and generally permitted lower-risk use. The categories are defined by the intended work, customer ownership, computing scale, and security measures. A joint technical panel reviews the thresholds every six months, with any change taking effect only after both governments published it through their own legal systems.
Remote access would follow the same rules as physical shipment. Data centers in third countries that sold high-capability computing to covered customers verify ownership, record the scale and duration of large training runs, and block prohibited military work. Independent auditors accredited by each government examine those records. They report compliance findings without receiving model weights, source code, student data, or ordinary user prompts. Deliberate evasion leads to loss of access and enforcement by the country with jurisdiction over the supplier or customer.
In return, Washington would publish a reliable path for licensing legitimate civilian projects, with decision deadlines and written reasons for denials. Beijing permits compliance checks for Chinese firms using licensed foreign computing and stops directing companies to disguise ownership through intermediaries. Both sides publish aggregate figures on approvals, denials, audits, and violations. These reports let each government test whether the bargain was working without forcing either to abandon its industrial strategy.
The model-testing part could build on work already under way in the private sector. In September, “Anthropic, Google and OpenAI aim to launch a standards body focused on artificial intelligence (AI) by the end of this year or early next year” (PYMNTS, 2026). Its proposed functions were concrete: “The standards body would support third-party organizations that test models before they are deployed, would detail how AI developers should report safety and security incidents, would define the labs’ voluntary safety and security commitments, and would establish qualifications for independent auditors of models and labs” (PYMNTS, 2026). The same report said, “Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman addressed a United Nations Security Council meeting focused on concerns about AI and agreed that there is a need for global standards to address potential risks around the technology.” (PYMNTS, 2026).
The hypothetical summit would turn those emerging practices into a reciprocal U.S.-China system. Developers seeking access to the licensed high-capability category submit their models to accredited independent testing before broad deployment. Tests cover the ability to assist cyberattacks, evade human oversight, reproduce dangerous capabilities, and conceal actions from operators. Each lab keeps its intellectual property. Regulators receive standardized test summaries, serious-incident reports, and proof that identified failures had been addressed. A bilateral review board compares methods and publish common minimum requirements. Trump could describe the arrangement as reciprocal market access enforced under U.S. law. Xi could point to measurable human control and public benefit.
The summit’s small trade agreement showed that reciprocal treatment for “non-sensitive goods” was possible (USA Today, 2026). The same structure could have supported AI: firm limits for military use and high-risk computing, clearer channels for civilian work, and common evidence about model behavior. Competition would continue under rules that make evasion harder and safety claims easier to check.
For schools, colleges, and educational technology providers, these agreements would affect decisions. Independent test summaries help institutions compare systems before putting them in classrooms. Incident-reporting rules tell administrators when a model had suffered a serious security failure. A clear human-authority principle supports local policies requiring teachers and qualified staff to make consequential decisions about students. Audits that exclude student prompts and data show that safety review can proceed without turning sensitive educational records into inspection material.
The broader benefit would be steadier planning. A school that chooses cloud-delivered AI also relies on remote computing services, advanced chips, and model providers governed across national borders (PYMNTS, 2026; Reuters, 2026c). A functioning hotline could keep a technical accident from becoming a political crisis. A human-control declaration could establish a firm limit where errors carry the greatest stakes. A balanced system for chips and model testing could preserve civilian access while giving governments evidence about dangerous uses. The Washington summit promised another conversation in November (USA Today, 2026). A truly successful summit would have left the world with signed duties, deadlines, tests, and records that people could examine.
References
PYMNTS. (2026, September 24). OpenAI, Google, Anthropic join forces to set AI safety standards. https://www.pymnts.com/news/artificial-intelligence/2026/openai-google-and-anthropic-join-forces-to-set-ai-safety-standards/
Reuters. (2026a, September 24). Trump says he’ll discuss AI with Xi but wants to “leave it exactly where it is”. https://www.reuters.com/business/media-telecom/trump-says-hell-discuss-ai-with-xi-wants-leave-it-exactly-where-it-is-2026-09-24/
Reuters. (2026b, September 17). US, China security experts propose nuclear-style safeguards for AI risks. https://www.reuters.com/world/china/us-china-security-experts-propose-nuclear-style-safeguards-ai-risks-2026-09-17/
Reuters. (2026c, September 23). What’s the latest with semiconductor export controls? https://www.reuters.com/legal/legalindustry/whats-latest-with-semiconductor-export-controls–pracin-2026-09-23/
SFG Media. (2026, September 24). Xi Jinping said at the White House that AI development must remain under human control. https://sfg.media/en/a/xi-ai-human-control-tariff-truce-2027/
USA Today. (2026, September 26). No breakthrough AI agreement between Trump and Xi during US-China summit. https://www.usatoday.com/story/news/politics/2026/09/26/trump-xi-ai-technology-china-us/91957387007/
The White House. (2026, September 22). President Trump at the United Nations: “While others have talked, I have acted.” https://www.whitehouse.gov/releases/2026/09/president-trump-at-the-united-nations-while-others-have-talked-i-have-acted/
###
Filed under: Uncategorized |


































































































































































































































































































































































































































































































































































Leave a Reply