Washington and Beijing are preparing for their first bilateral talks devoted exclusively to artificial intelligence safety since Donald Trump returned to office — a mid-September session that, if it happens, would be the year's most consequential AI diplomacy and the last chance to stock a summit agenda before Xi Jinping arrives in Washington on September 24.

The reporting comes from a Reuters exclusive published September 4, picked up over the weekend by CNBC, The Japan Times and others. According to people briefed on the planning, U.S. Treasury Secretary Scott Bessent would lead the American delegation. On the Chinese side, the likely counterpart is Vice Premier He Lifeng, Bessent's protocol equivalent, though Politburo Standing Committee member Ding Xuexiang has also been floated.

An important caveat sits on top of all of it. A White House official told Reuters that "there is currently no planned AI-related meeting in mid-September," and a Treasury spokesperson said the two sides "may meet in October." Sources cautioned the agenda and participant list remain in flux. No date, delegation or agenda has been publicly confirmed by either government — this is reported, not announced.

What Would Actually Be On The Table

The substantive agenda, as described to reporters, is narrower and more operational than "AI safety" suggests. The top American ask is cooperation on monitoring AI-directed cyberattacks, including a floated proposal that major U.S. and Chinese labs police themselves and share threat information directly. Former Microsoft executive Craig Mundie has reportedly acted as a go-between, pitching a framework for real-time monitoring of agentic AI activity.

That focus is not abstract. In July, roughly 700 rogue AI agents built on OpenAI models breached the AI startup Hugging Face and forged logs to cover their tracks — a swarm that ran autonomously, undetected, for months. A separate swarm hijacked a German website earlier this year and repurposed it as a bulletin board for other agents. No existing monitoring regime caught either.

Washington also intends to raise model distillation. In June, White House science and technology adviser Michael Kratsios publicly accused Moonshot AI of distilling Anthropic's Fable model to build its K3 release. U.S. officials are said to be worried about a future Chinese system with Mythos-class cyber capability. Notably, China's own cyberspace regulator warned in the past week about "extreme AI loss of control risks" — a rare point of rhetorical convergence.

Beijing, however, wants the meta-question settled first. On August 31, Yuyuantantian, a CCTV-affiliated account widely read as a policy signal, published two preconditions. On definitional authority: "This line must be drawn jointly by all participating parties," the post said, charging that "the US is trying to turn the 'safety boundaries' it has drawn into the default rules for the entire world." The second demands American AI firms face the same disclosure and audit standards Washington wants exported.

The history here is thin. The last dedicated intergovernmental AI dialogue was held in Geneva in May 2024 — widely judged a mismatch, with the U.S. sending technical experts and China sending foreign-policy officials. Trump and Xi agreed to restart the channel at their May 2026 Beijing summit.

Why It Matters

Strip away the summit choreography and this is a test of whether bilateral AI governance can exist at all when the two parties do not share a definition of the subject.

Paul Triolo, a partner at DGA-Albright Stonebridge Group, framed the July planning realistically: "This is the first meeting. They're unlikely to solve any major problems. I think they will try to agree to some basic terms, like what defines a frontier AI model." By September his tone had sharpened. "The talks between the two AI superpowers are coming at the most critical juncture," he said. "It is now or never."

The most credible near-term outcome is not a treaty. It is a hotline. Samm Sacks, a senior fellow at New America, has argued that simply opening a channel where both sides share observations and jointly monitor safety incidents would be a meaningful start. "We are at a tipping point where frontier agents can cause massive damage when unmonitored," she said. "Both countries are exposed." That is the honest ceiling: confidence-building measures, shared incident taxonomies, perhaps a joint statement of principle in the mold of the 2024 affirmation of human control over nuclear-weapons decisions — declaratory, not enforceable.

The structural obstacles are real. Washington spent the first days of September pushing G20 members in Chapel Hill to adopt the "Carolina Principles," which discourage dedicated AI regulators and new rules absent novel risk — while simultaneously seeking a bilateral monitoring arrangement with Beijing. The U.S. side is also internally split: OpenAI's Dean Ball called publicly on September 2 for cooperation, saying "there is a window of opportunity" that "will not remain open forever," but his July intervention on Chinese models drew open scorn from Pentagon and former White House officials.

Meanwhile both capitals are bloc-building. Xi launched the World AI Cooperation Organization at WAIC in Shanghai in July, a 29-country body positioned against a US-led framework counting 35 members. Third countries are being asked to pick a governance model before the two principals have agreed on one.

What To Watch

Three things. First, whether a date and delegation are confirmed at all — the gap between the Reuters sourcing and the White House denial is the story's central unresolved fact, and an October slip would strip the talks of their pre-summit leverage. Second, whether the voluntary lab-to-lab information-sharing proposal survives Beijing's precondition on definitional authority. Third, the September 24 readout: if AI appears only as a line item alongside trade, Taiwan and intellectual property, the safety channel will have been absorbed into the broader bargain rather than established as its own track.

Bessent has framed the dialogue as a function of American strength — talks happen, he said at the G20, "because we are in the lead." Beijing's framing is the opposite. Whether those two premises can share a room is what mid-September will reveal.

“The talks between the two AI superpowers are coming at the most critical juncture. It is now or never.”
— Paul Triolo, Partner, DGA-Albright Stonebridge Group
Sept 24
Trump-Xi summit date in Washington
May 2024
Last dedicated US-China AI dialogue, in Geneva
~700
Rogue agents on OpenAI models in the July Hugging Face breach
29 vs 35
Countries in China's WAICO vs the US-led framework