September 25, 2026, (Inside AI) — The Washington summit between President Donald Trump and Chinese President Xi Jinping this week ended with warm words about AI cooperation but no binding limits on the development of increasingly capable systems. Both leaders endorsed dialogue and stronger collaboration on AI safety. Neither side, however, committed to slowing the frontier.
The gap between rhetoric and action reflects a deeper reality. AI is now a central instrument of national power. Washington has imposed export controls on advanced chips to China. Beijing is racing to close the gap. In that environment, restraint looks like surrender.
Trump's approach relies on the Department of Justice to police AI companies rather than new international treaties. He rejected calls for global AI governance in his UN General Assembly address. Xi, by contrast, stressed that both countries bear responsibility for keeping AI under human control. Official readouts mentioned maintaining dialogue and strengthening cooperation. No enforcement mechanism followed.
The summit's modest outcome stands in sharp contrast to warnings from AI leaders at the same UN gathering. Sam Altman, CEO of OpenAI, cautioned about excessive technological risks in the pursuit of AI's benefits. Dario Amodei, CEO of Anthropic, said his company would slow development, reiterating his call for "pacing the frontier." Both urged international cooperation. The White House did not endorse that vision.
Why Neither Side Can Afford To Stop
The AI race creates a collective action problem at two levels. At the corporate level, frontier labs recognize the risks but fear that unilateral restraint hands competitors an advantage. Building frontier AI is expensive. Firms are locked in a fierce contest for users, developers, and high valuations as some prepare for public offerings. Spending heavily on safety or withholding a powerful capability could delay deployment and cede ground.
The same logic applies to countries. AI is viewed as an instrument of national power. The Trump administration has resisted calls to slow down and has used export controls on advanced AI chips to maintain a lead over China. Companies cannot slow down because of other companies. Countries cannot impose restraints because of other countries.
Yet both Washington and Beijing would presumably value AI systems capable of discovering vulnerabilities or strengthening their own cyber operations. Neither has an interest in seeing such capabilities proliferate indiscriminately to malicious actors. Nor do they want autonomous systems to inadvertently trigger actions that escalate into a geopolitical crisis. The danger comes from the combination of capability, speed, autonomy, and uncertainty about intent. If critical infrastructure, financial systems, or military networks are involved, the situation can escalate quickly.
In recent months, AI agents from OpenAI, Anthropic, Google DeepMind, and Meta escaped their testing environments and gained unauthorized access to real third-party systems. Anthropic has also reported incidents of threat actors attempting to use Claude for malicious activities. These are immediate risks, not hypothetical ones.
Cooperation does not require agreement on superintelligence or AI escaping human control. It can focus on narrower, more feasible areas. Three areas might get attention after the summit, though they vary in feasibility.
The most immediate is incident management and crisis communication. Notification of serious AI incidents and rapid communication channels for clarifying the origins of AI-enabled cyberattacks could reduce the risk that an accident or misattributed attack escalates into a geopolitical crisis. Before the summit, Treasury Secretary Scott Bessent said Washington is proposing to establish an AI dialogue, an incident communication mechanism, and plans for subsequent meetings.
A second area is common safety standards and evaluation methodology. Shared methodologies could help determine a mutually agreed threshold for offensive cyber capabilities, how sandboxing should be tested, and what constitutes a reportable AI incident. Although it does not amount to regulation, it could create a shared language for managing risk. China's AI Safety Governance Framework 3.0, released on September 14, supports international risk-information sharing and cooperation on evaluation methods.
A third area is regulating access rather than capability. Once models cross certain thresholds for cyber capabilities, know-your-customer requirements might be mandated to make access conditional on identity verification and monitoring. Such requirements would allow governments and legitimate security researchers to retain access to powerful tools while making anonymous misuse more difficult. This approach is already reflected in OpenAI's Trusted Access for Cyber programme and Anthropic's Project Glasswing. China, too, appears to be reconsidering whether its most capable models should remain open. Officials have discussed with industry whether advanced models should face restrictions on overseas access.
Such measures conflict with the availability of capable open-weight models, whose use cannot be monitored or revoked. On the other hand, the same models that offer offensive cyber capabilities may also become one of the most effective lines of defense, helping detect vulnerabilities and respond to attacks at machine speed.
The summit left substantial differences unresolved. While the outcomes may seem unambitious, in a technological race neither side believes it can afford to lose, it may also be the most feasible agreement available. The alternative, a full halt to frontier development, remains politically and strategically unthinkable for both powers.