Artificial intelligence is becoming a national-security system before governments have built the communications channels needed to manage a failure. That makes a new U.S. proposal for an AI incident-notification mechanism with China more important than its modest name suggests.
After weekend talks in New York, U.S. Treasury Secretary Scott Bessent said Washington had proposed a way for the world’s two largest AI powers to alert each other about incidents that could affect national security. The idea surfaced ahead of meetings between U.S. President Donald Trump and Chinese President Xi Jinping. Details remain thin, and there is no agreement yet. Still, the premise is sound: opacity is dangerous when software can act quickly, cross borders and be mistaken for deliberate human action.
Hotlines exist because rivals misread each other
The value of an incident channel is not trust. It is the opposite. Rivals need a reliable way to exchange narrow, verifiable facts precisely because they do not trust each other’s intentions. A malfunctioning autonomous system, a compromised model or a synthetic message attributed to a government could create pressure to respond before analysts know what happened.
Traditional crisis hotlines were designed for weapons and military movements. AI adds a different kind of ambiguity. A model can generate persuasive false evidence, automate a cyber operation or behave unpredictably after deployment. The first sign of a problem may appear inside a private company, not a defense ministry. Governments therefore need protocols that connect national authorities to laboratories, cloud providers and critical-infrastructure operators without turning every technical failure into a geopolitical accusation.
The hard part is defining an incident
A useful mechanism would need strict thresholds. Minor service outages and routine security bugs do not belong on a diplomatic hotline. Incidents involving unauthorized access to sensitive systems, uncontrolled model behavior, large-scale deception, interference with critical infrastructure or credible national-security consequences probably do.
It would also need a shared reporting template: what system was involved, when the event began, what capabilities were observed, whether the system remains active and what evidence can be disclosed. The first notification should be fast and factual. Attribution, blame and public messaging can come later.
Verification will be difficult. Companies may resist revealing failures, while governments may fear exposing intelligence sources or giving a rival useful technical details. A narrowly scoped channel will not solve those incentives. It can, however, create an expectation that silence is not the default when an AI event could be mistaken for an attack.
Competition still needs guardrails
The United States and China are not about to stop competing over chips, models, talent or military applications. They do not need to agree on broad AI regulation before establishing a basic warning system. Aviation rivals still share safety information. Nuclear competitors built hotlines without becoming allies. Practical risk reduction can coexist with strategic competition.
The worst time to invent this channel is after a model-generated deception, cyber incident or autonomous-system failure has already created a crisis. An AI hotline will not make powerful systems safe. It may give human decision-makers the few extra minutes and verified facts needed to keep a machine error from becoming a political one.
Sources: Associated Press reporting on the proposed U.S.-China notification mechanism; The Atlantic’s summit preview and discussion of the proposal.