US-China Tech Competition and AI Safety: Rivalry, Restraint, and the Future of Frontier AI Governance
By Aryamehr Fattahi | 30 September 2026
Summary
Chinese President Xi Jinping's state visit to the United States (US) created new standing US-China channels on Artificial Intelligence (AI) risk: a Super Intelligence (SI) Dialogue, an incident channel and a pledge on military crisis communications, alongside tariff cuts on USD 30b of goods in each direction and a trade truce extended to 10 January 2027.
The new architecture manages accidents at the edges of the competition rather than restraining it. Export controls, distillation and the pace of development all sit outside it, and its core terms remain undefined.
Huawei, hedging third countries, and Beijing's diplomatic standing stand to gain most, while Nvidia and advocates of slowing frontier development lose ground. The main risks are a disputed incident exposing the channel's ambiguity and safety becoming a bargaining chip in trade talks.
The first dialogue round is highly likely to take place by November 2026 and to yield procedural outcomes. A binding bilateral limit on frontier development is highly unlikely before 2028.
Context
US-China technology competition now spans chips, models, standards and influence in third countries. The size of the US lead is contested, and US President Donald Trump puts it at "at least a year, maybe a year and a half". On chips, ByteDance and Tencent each received about 10,000 Nvidia H200 units, compared with 75,000 licensed units, as Beijing capped purchases and steered firms toward Huawei's Ascend processors. Huawei and Cambricon now hold nearly 80% of China's domestic AI server market, and DeepSeek plans to deploy at least 160,000 Ascend chips.
Safety and security disputes intensified before the summit. China's AI Safety Governance Framework 3.0, published on 14 September 2026, addresses agentic AI, deception in evaluations and models disabling shutdown scripts. It is non-binding, but a mandatory agent safety standard is in drafting. US security agencies accused 6 Chinese firms, including DeepSeek and Alibaba, of industrial-scale distillation of US models. China's Ministry of Commerce called distillation standard practice and threatened countermeasures. Anthropic Chief Executive Officer Dario Amodei proposed to "pace the frontier" through embedded evaluators and coordinated limits. US and Chinese experts proposed that humans retain control over AI-enabled cyberattacks on nuclear command systems. Carla Freeman of Johns Hopkins University expects Chinese officials to await leadership direction before engaging, which may take days.
Xi's state visit to the US ran from 23 to 25 September 2026. The White House fact sheet created the SI Dialogue, with a first exchange in November, and a channel for "SI incidents" that it does not define. China's Foreign Ministry will keep using "artificial intelligence", and the 2 militaries will conclude a crisis communications memorandum "as soon as possible", with no deadline. US Trade Representative Jamieson Greer kept national security export controls "off the table", and Trump ruled out "putting on the brakes". White House Office of Science and Technology Policy Director Michael Kratsios ruled out any drift "toward global governance". The summit also extended the trade truce to 10 January 2027 and cut tariffs on USD 30b of goods in each direction.
Third countries are hedging. Saudi Arabia built an Arabic model on MiniMax's open-source system while investing in Nvidia-based infrastructure, and Brazil split its AI budget between Huawei-backed and Nvidia-based systems. The US-led Pax Silica offers invitation-only supply chain access, while China's World AI Cooperation Organisation (WAICO) presents itself as open and complementary to the United Nations (UN).
Implications
The summit matters less for what it settled than for what it left out, and that shapes who gains and who loses.
Safety as a Stabiliser, Not a Brake
The new channels are likely to lower the cost of accidents without changing the pace of frontier development. Excluding export controls confirms that Washington treats its compute advantage as non-negotiable. Beijing gains parity of status in a forum that asks nothing of its industrial policy. The timing also ties safety to trade sentiment. A lapse of the truce on 10 January 2027 would create a realistic possibility of the dialogue freezing, making safety a bargaining chip. Sceptics doubt that rivals will share sensitive incident data at all. Even so, a channel that averts 1 misread cyber event would justify its modest cost.
Ambiguity Is the Main Point of Failure
The undefined terms are highly likely to be where the arrangement is first tested. Without an agreed threshold, either side can reclassify an event as commercial or domestic and withhold notice. The naming dispute is substantive rather than cosmetic. A "super intelligence" frame points to frontier capability risks. China's broader "AI" frame covers misuse, content and deployment. The 2 frames imply different incident lists. No published commitment is binding, and neither side can verify the other's reporting. Verification is harder still when agents run on cloud infrastructure in third countries. The likeliest early failure is a contested notification, such as an intrusion traced to a Chinese-linked model. That would turn the channel into a venue for accusation.
Chips and Distillation: The Contest Outside the Room
Keeping chips off the agenda leaves the sharpest conflicts unmanaged and accelerates Chinese substitution. Beijing, not Washington, is now the binding constraint on Nvidia's China sales. Huawei is the clearest winner, since state-steered demand validates Ascend despite supply shortfalls. Nvidia and its investors lose a market that is unlikely to return at scale. Distillation is the more dangerous flashpoint because it blends security, commerce and safety. Distilled models can inherit capabilities without the safety training of the original. Sanctions on named firms would invite the countermeasures Beijing has threatened. The contested size of the US lead raises the stakes further. If the gap is months rather than years, Washington is likely to treat distillation as erosion of its main advantage.
Shared Vocabulary, No Shared Speed Limit
Technical convergence on risk is genuine but unlikely to produce restraint. Framework 3.0's focus on shutdown resistance, sandbagging and agent permissions mirrors concerns at Western labs. That overlap gives the dialogue a common technical agenda. However, the framework is silent on what a failed safety test should trigger. A binding Chinese agent standard would be a stronger signal than any dialogue statement. Both governments voice concern about loss of control while prioritising speed. Neither is likely to slow while believing the other will not. Amodei's proposal is therefore stronger on diagnosis than on incentives. Bilateral pacing is a remote chance, and shared evaluation methods for agentic systems are the more plausible outcome.
Governance: Rival Clubs and a Hedging Middle
The US rejection of global governance is likely to transfer multilateral agenda-setting to China, while the US retains the harder assets. Pax Silica offers trusted partners chips and supply chain security. WAICO and UN-centred diplomacy offer the Global South a voice at low cost. Most third countries are unlikely to choose. Pairing US chips with Chinese open-weight models is rational for cost-sensitive states, and it erodes the leverage of both blocs. US allies gain from lower escalation risk. They lose influence if a bilateral channel sidelines their own AI safety institutes. A second-order risk is that Chinese open models become embedded infrastructure before any shared safety standard exists.
Military AI: Highest Stakes, Least Substance
Military AI is where the dialogue matters most and has delivered least. The memorandum has no text or deadline, which suggests it remains aspirational. Existing commitments on human control over nuclear use do not cover AI-enabled cyber operations against nuclear command systems. That gap matters because such attacks could escalate faster than humans can intervene. Beijing's habit of awaiting leadership direction before engaging also limits any hotline's speed. A new line would still add value if it carried pre-agreed incident categories. Meanwhile, defence planners on both sides are highly likely to keep integrating AI into decision support. Norm-setting is therefore likely to trail deployment.
Forecast
Short-term (Now - 3 months)
The first SI Dialogue round is highly likely to take place by the end of November 2026. It is likely to produce a statement on incident categories rather than a working protocol. New US measures against named distillation firms are a realistic possibility and would test the channel early.
Medium-term (3 - 12 months)
Extension of the trade truce beyond 10 January 2027 is likely, which would keep the dialogue alive. A signed military crisis communications memorandum is a realistic possibility, but explicit AI provisions within it are unlikely. Huawei's domestic market share is highly likely to keep rising as H200 imports stay marginal.
Long-term (>1 year)
A binding bilateral limit on frontier development is highly unlikely before 2028. A narrow pledge on human control over AI-enabled attacks on nuclear command systems is a realistic possibility by 2029, most probably after a serious incident. The split between a US-aligned compute bloc and a Global South running Chinese open models is likely to deepen through 2028.