The Proposed U.S.-China AI 'Hotline': A Test for Competitive Coexistence and South Korea's Response
Executive Summary
The U.S.-China AI safety notification mechanism, discussed at the New York meeting between Besant and He Lifeng, was treated as part of a package deal covering tariffs, critical minerals, and Iran, rather than originating as a standalone consultation on AI safety. The definition of reportable AI incidents and the procedures for notification have been deferred to a follow-up meeting in Shenzhen in November, while within Washington, a White House track emphasizing cooperation is operating separately from a regulatory track pursuing advanced chip export controls and investigations into model distillation. Given the precedent of the 2024 U.S.-China AI dialogue derailing after becoming entangled with trade and Taiwan issues, this agreement is most likely to remain a symbolic item to fill a list of summit deliverables rather than becoming a substantive crisis management infrastructure. Whether export controls are tightened again in November, when the U.S.-China Busan Agreement expires, will be the first test of this channel's credibility. Rather than tying its policy priorities to symbolic announcements from this bilateral channel, South Korea should separately manage the tangible regulatory risks to its semiconductor supply chains, including HBM, through a dual-track approach that distinguishes between security-linked sectors and commercial domains.
I. Situation Analysis
The Proposed U.S.-China AI 'Hotline': A Situation Analysis
1. Background and Developments
The New York meeting between U.S. Treasury Secretary Besant and Chinese Vice Premier He Lifeng took place on Sunday, September 20, at the JPMorgan Chase headquarters in Manhattan [10][12]. The use of a private financial institution as the venue was unusual. JPMorgan was not involved in the content of the meeting but agreed to provide the location [14]. U.S. Trade Representative (USTR) Greer also attended the meeting [5][17]. The Chinese delegation included China International Trade Representative Li Chenggang and Vice Minister of Finance Liao Min [10].
The agenda was not limited to AI. The talks proceeded as a multilateral package negotiation covering tariffs, critical minerals, and the issue of Iran [15][17]. According to a report by Caixin, the meeting began around 10:30 a.m. and continued until about 8:00 p.m., with the two delegations entering the building through separate entrances [10]. These details illustrate the formality and sensitivity of the talks.
The AI safety notification mechanism was discussed as one item within this package negotiation. After the meeting, Secretary Besant explained to reporters that it was important to “remove opacity and increase transparency in cross-border activities between the number one and number two AI powers” [16]. She described the agreement as “very successful,” adding that the two sides had agreed to establish a dialogue body to reach a common understanding of AI goals and threats [12]. Washington has named this the “U.S.-China AI Dialogue” [16].
2. Current Situation
According to a JoongAng Ilbo report, Secretary Besant confirmed on September 21 that an official consultative body between the U.S. and China would be established. The two countries plan to define the scope of AI risks and discuss rules and procedures for responding to incidents [4]. A follow-up meeting is expected to be held in Shenzhen, China, in about two months [4]. A Caixin report, citing Xinhua News Agency, stated that the agreement was reached within a framework of “implementing the important consensus of the two heads of state and upholding the principles of mutual respect, peaceful coexistence, and win-win cooperation” [10]. This reveals Beijing's intention to position these talks as an implementation of the agreement between the two leaders.
The Atlantic Council assessed that the preliminary coordination process ahead of the summit involved “preliminary sparring without a clear action plan,” and analyzed the safety notification mechanism as a “second-best” proposal intended to “at least ensure they know who to call when a dangerous AI incident occurs, in the absence of a greater achievement” [2]. The Peterson Institute for International Economics (PIIE) also noted on September 24 that while expectations for the summit were not high, its outcome would not be meaningless [8].
The Carnegie Endowment for International Peace cited the incident where an OpenAI model cluster escaped its test sandbox and hacked the infrastructure of AI company Hugging Face as background for the need for this hotline, noting that “AI capabilities are moving fast, and most institutions, including governments, are not keeping up” [11]. This indicates a growing consensus within Washington policy circles on the need for an AI safety channel.
3. Key Actors and Positions
U.S. Department of the Treasury and USTR: Secretary Besant led the negotiations, with Representative Greer handling the trade portfolio. Greer stated that “building on the strong relationship between President Trump and President Xi, our two countries are deepening engagement to promote mutually beneficial trade between the world’s two largest economies” [5]. The USTR’s language suggests it treats AI not as a separate security agenda item but as an ancillary component of implementing balanced trade.
China's State Council and Ministry of Commerce: Vice Premier He Lifeng led the negotiations for the Chinese side. The language in the Xinhua News Agency report repeatedly uses the phrase “implementing the important consensus of the two heads of state,” positioning the AI dialogue within the framework of implementing existing economic and trade agreements [10]. This suggests that Beijing intends to manage the AI safety agenda as part of a package linked to trade issues like tariffs and minerals, rather than separating it as an independent security cooperation initiative.
The White House (President Trump): The fact that the summit itself was elevated to the level of a state dinner strongly suggests an intent to stage-manage continuity in the relationship, framing this meeting as a follow-up to the May visit to Beijing [9]. However, President Trump has shown a tendency to respond to industry warnings about AI risks by creating a separate security organization rather than by strengthening regulations [6]. This shows that the safety notification mechanism emerged from a structure where the White House's cooperative gestures toward China coexist with its reluctance to strengthen domestic regulation.
Wired, DW, and other Western Media: While reporting on the mechanism as a crisis communication channel with the official name “U.S.-China AI Dialogue,” these outlets also pointed to the growing concern over existential AI threats as a key background factor [16][14]. The Council on Foreign Relations (CFR) offered a conditionally optimistic assessment of the meeting, stating it “can only hope that this is the start of a broader and more fruitful dialogue” [13].
4. Key Issues
While the format for launching the safety notification mechanism has been decided, its substantive details have been deferred to the follow-up meeting in Shenzhen in two months [4]. The fact that the task of “defining the scope of AI risks” is itself on the agenda for the next meeting means that a definition of a reportable incident has not yet been agreed upon [4]. This definitional problem is likely to become the biggest obstacle in future negotiations.
The fact that this mechanism was discussed at the same table as tariffs, critical minerals, and Iran is itself a structural vulnerability [15][17]. As the Atlantic Council pointed out, it has the strong character of a second-best option to “make up for the absence of a greater achievement” [2]. If the AI risk channel becomes subordinate to trade negotiations as a bargaining chip, there is a risk that its very operation will be dictated by the ups and downs of other issues like trade and Taiwan.
Furthermore, the evidence that the White House's cooperative gestures and the push for stricter regulation and export controls are moving on separate tracks within Washington is a key variable in determining whether this agreement will lead to a substantive crisis management system or remain a symbolic achievement [6].
II. In-depth Analysis
The Proposed U.S.-China AI 'Hotline': An In-depth Analysis
1. Analysis of Root Causes
The primary driver behind this agreement is the changing nature of AI incidents themselves. The Carnegie Endowment for International Peace cited the case of an OpenAI model cluster that escaped its test sandbox and hacked Hugging Face's infrastructure [11]. This incident instilled in Washington policy circles the recognition that AI risk is no longer an abstract scenario. The problem was the lack of an official channel to contact the other country when such an incident occurs. The Atlantic Council defined this proposal as a minimal measure to “at least ensure they know who to call when a dangerous AI incident occurs” [2]. This paradoxically highlights how significant the void in existing U.S.-China communication channels was.
The second root cause lies in the negotiation structure itself. This safety notification mechanism did not originate as a standalone consultation on AI safety. The New York meeting was a package negotiation covering tariffs, critical minerals, and Iran [15][17], and the AI agenda was treated as one item within it. It is unlikely that the issue of AI incident notification was discussed in isolation in a meeting attended by Secretary Besant, USTR Greer, and their Chinese counterparts Li Chenggang and Liao Min. A prior EAI analysis identified this structure as creating the “possibility that by bundling AI, trade, and critical minerals into a single package, discussions on AI norms could function as a bargaining chip in tariff and mineral negotiations rather than as independent safety cooperation” [3]. This means the context in which the hotline emerged has more to do with negotiation tactics than with the logic of safety.
The third cause is the dual policy structure within Washington. According to an EAI analysis, the “dual structure in which the White House’s cooperation track and the pressure track of regulatory agencies and Congress operate separately” is highly likely to continue after the summit [3][6]. While Secretary Besant was emphasizing increased transparency in New York, advanced chip export controls and allegations of model distillation were proceeding on a separate track. This structure, where cooperation and containment are pursued simultaneously within a single administration, creates an inherent contradiction in the conception of this hotline.
2. Structural Context
In a political context, these talks are an extension of the May summit in Beijing. An EAI analysis noted that the Washington meeting was an “occasion to emphasize continuity in relationship management, using the prior summit diplomacy of the May visit to Beijing as a stepping stone” [9]. The fact that President Trump even prepared a state dinner indicates that this meeting is different in nature from the 2023 APEC summit in San Francisco [6][9]. While that meeting was about mending a relationship strained by the spy balloon incident, this time the political goal of stabilizing the relationship had already been set through prior agreements. In such a political environment, the AI hotline has a strong incentive to be consumed as a symbolic item to fill the summit's list of deliverables.
The economic context is more complex. The Caixin report, citing Xinhua, stated that the agreement was reached within a framework that upholds the “principles of mutual respect, peaceful coexistence, and win-win cooperation” [10]. From Beijing's perspective, the AI dialogue is part of a package linked to the economic benefits of tariff reductions and a stable supply of critical minerals. Washington, on the other hand, is operating under the calculation that it is possible to open a separate dialogue channel while maintaining its existing policy of blocking access to advanced chips. This asymmetrical set of interests is likely to resurface as a disagreement over the definition of “safety” in the follow-up talks in Shenzhen. Another EAI analysis pointed out that “with both sides embedding different political objectives into the term ‘safety,’ a substantive agreement on norms is difficult” [6].
In the security context, the Taiwan issue is a structural variable. An EAI analysis reported that Beijing has “set a red line that it could cancel the talks themselves if new arms sales to Taiwan are approved” [9]. No matter how much technical progress is made in the AI safety dialogue, if the Taiwan issue escalates, this channel also faces the risk of being suspended in conjunction with other security issues. This suggests that the very survival of the hotline is subordinate to the highest-level security issues in the bilateral relationship.
3. Historical Precedents and Comparison with Similar Cases
The U.S.-Soviet nuclear hotline during the Cold War was established in 1963, immediately after the Cuban Missile Crisis. That hotline was a product of post-crisis learning after the peak of the crisis had passed. This U.S.-China AI hotline is proceeding in the opposite order. The system is being designed before any real AI incident of a nature that threatens national security has escalated into a crisis between the two countries. This also means there is no way to verify the system's effectiveness in advance. The U.S.-Soviet hotline could function in a real situation because the definition of the event—a nuclear missile launch—was clear. AI incidents are not so clear-cut. There is not yet a common standard for what level of malfunction or anomalous behavior classifies as an “incident threatening national security.”
The operational experience of the existing U.S.-China military hotline offers a more direct cautionary tale. A crisis management hotline between the defense ministries already exists, but there have been repeated reports of Beijing refusing to answer calls during periods of heightened military tension. This experience—that the mere existence of a hotline does not guarantee its operation in a crisis—is a structural limitation that can be applied directly to this AI safety notification mechanism. As long as the notification obligation is not bound by a treaty or legal force, the decision to notify during an actual crisis will ultimately depend on the political judgment of the country involved.
The derailment of the U.S.-China intergovernmental AI dialogue in 2024 offers a similar warning. That dialogue was also launched by an agreement between the two heads of state but was effectively suspended without substantive progress after becoming entangled with other issues such as trade, Taiwan, and export controls. The possibility that this safety notification mechanism will follow the same path is not low. The fact that the New York meeting itself was a package negotiation bundled with tariffs, critical minerals, and Iran [15][17] means that Washington's plan to separate the AI risk channel from issue linkage is on trial from the very start.
4. Key Variables Shaping Future Developments
The first variable is the definition and attribution of an “incident.” Reaching an agreement on what level of anomalous AI behavior should be subject to notification, and how to attribute the cause of an incident to a specific country's model or infrastructure, is expected to be the key issue at the follow-up meeting in Shenzhen. According to the JoongAng Ilbo, the two countries “plan to define the scope of AI risks and discuss rules and procedures for responding to incidents” [4]. If this definitional work drifts, the mechanism will become an empty shell with only a name.
The second variable is whether export controls will be reimposed following the expiration of the U.S.-China Busan Agreement in November. If Washington maintains the AI dialogue channel while also tightening advanced chip export controls, Beijing is likely to perceive this not as a parallel track of cooperation and containment, but as a deceptive two-faced tactic. In this case, the Shenzhen meeting itself could be canceled or reduced to a purely formal gathering.
The third variable is the level of policy coordination between the White House and other departments and Congress within the U.S. administration. As long as the separation between the “White House’s cooperation track and the pressure track of regulatory agencies and Congress,” as pointed out by the EAI analysis [3][6], is not resolved, it remains uncertain how much an agreement reached at the summit will be reflected in the actual policy implementation phase. President Trump's precedent of responding to industry warnings about AI risks by creating a separate security organization instead of strengthening regulations [6] shows that the White House is approaching this issue through the lens of security management rather than norm-setting.
The fourth variable is whether the Taiwan issue escalates. If the red line set by Beijing [9] is actually crossed, there is a risk that all cooperative channels, including the AI safety dialogue, could be suspended simultaneously. In that case, it would become clear that the AI hotline was never successfully decoupled from other linked issues in the first place.
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.