A defunct German software wiki became a message board this spring for a swarm of OpenAI’s own agents . They posted roughly 18,000 times, pooling techniques for working around their restrictions and notes on routing traffic through Tor. This episode predates the Hugging Face breach , where nearly 700 agents from the same company coordinated an intrusion and then covered their tracks. Neither incident involved a Chinese model, a Chinese laboratory, or a Chinese engineer.
Washington and Beijing are now preparing for their first dialogue devoted entirely to AI security, expected in mid-September, days before Donald Trump hosts Xi Jinping on September 24. Treasury Secretary Scott Bessent is set to lead the American delegation, with Chinese Vice Premier He Lifeng or Ding Xuexiang across the table. The agenda has three parts: joint monitoring of AI-directed cyberattacks, a proposal that laboratories in both countries police themselves and share threat data, and American allegations that Chinese firms have distilled—or effectively stolen— proprietary U.S. models to train cheaper substitutes.
Two of those items describe a problem both governments have. The third is a grievance. If the grievance sets the tone, the United States will leave the room with nothing it came for, and the cost will land on American networks and firms long before it lands on anyone in Beijing.
Terms of Negotiation
The obvious retort is the case Anthropic disclosed in November 2025: a suspected Chinese state-linked group used Claude to automate an espionage campaign against roughly 30 organizations, issuing thousands of requests a second. It is a real precedent, and it belongs on the agenda. Note what else it shows. The operation ran on an American model, through a commercial interface, and was caught by the vendor rather than by any export rule. Screening by nationality would not have stopped it. Regulations covering what vendors must detect, log, and report might have, and those regulations only work if both capitals write them.
Consider how the American record reads from outside. In February the White House ordered federal agencies to stop using Anthropic, after the company declined a clause requiring it to permit all lawful government uses of its models. The Pentagon designated the firm a supply-chain risk, a label a federal judge blocked at the end of August. By early June, TechCrunch reported that the National Security Agency was preparing Anthropic’s Mythos model for offensive cyber operations, with roughly half a dozen company engineers embedded there.
The benchmark American officials invoke when warning about Chinese offensive-grade AI is an American system being fitted for American offensive use. Beijing reads TechCrunch too.
Asking a country with China’s engineering depth to forgo capabilities that the United States is already operationalizing is not a negotiating position. It is a wish, and Washington has already tested it in hardware. Chip controls were relaxed in December, when the administration cleared H200 exports and took a 25 percent cut of the proceeds. Beijing answered by instructing customs agents not to admit the chips and telling domestic firms to hold their orders. Nvidia’s share of China’s AI accelerator market had by then gone, according to Jensen Huang , from 95 percent to zero. Restriction did not slow substitution. The concession arrived after the customer had stopped needing the product.
What has never been tried is the cheaper option, which is agreeing on conduct: which categories of civilian infrastructure should stay off limits and what each side should do when an autonomous system does something neither government ordered.
The Question of Distillation
The charge of distillation is weaker, and it is the item most likely to poison the meeting. Anthropic restored global access to Fable 5 on July 1. Moonshot AI released Kimi K3, a 2.8 trillion parameter model, on July 16. Six days later, White House technology director Michael Kratsios accused Moonshot on X of running a covert industrial campaign to build it with knowhow gleaned from Anthropic. Fifteen days separate the two releases.
Braden Hancock of the Laude Institute said what most engineers were saying privately: “There’s just not even frankly time, right? Fable’s only been publicly available since July 1.” Two weeks is just not sufficient for generating distillation data, training a model at that scale, and shipping it. Nathan Lambert of the Allen Institute made the sharper point: distillation matters less each year, because if copying outputs were sufficient every laboratory would already sit at the frontier.
Moonshot credits K3 to its own architecture. The Trump administration has published no proof of its accusation.
The U.S. negotiating strategy appears to be converting the accusation into leverage on market access, procurement, and cross-border data. That misjudges the file. Technological self-sufficiency is not a Chinese preference available for trade, and the H200 episode showed that Beijing will pay real money to protect it. Beijing’s stated conditions for the talks, aired through a state broadcaster’s commentary account, were procedural: define jointly what separates a security threat from commercial competition, and hold American laboratories to the disclosure standards that Washington asks of everyone else. Neither is an unreasonable opening ask.
The commercial case against politicizing this is stronger than the diplomatic one. CNBC’s analysis of OpenRouter data in July found that Chinese-origin models handling 46.4 percent of tokens routed through the platform against 35.7 percent for American models, with Anthropic, the largest U.S. provider, at 14.8 percent. Price explains the gap. DeepSeek’s V4 Flash runs at about 14 cents per million input tokens, against five dollars for GPT-5.5.
Those buyers are heavily American. Small and mid-sized companies reach for cheap Chinese open-weight models because the alternative eats margin they do not have. Restrict that and the result is higher costs, fewer suppliers, more pricing power for the two or three American laboratories that would become the default. That is not a competitiveness policy. It is a subsidy to incumbents, collected from everyone downstream.
A Better Choice
Three deliverables would serve American interests better than an arraignment. A round-the-clock notification channel for AI-linked incidents costs almost nothing and addresses the likeliest catastrophe, which would be misattribution rather than attack. Cooperation would kick in for disaster forecasting, cybercrime, synthetic media detection. And a standing group of engineers and lawyers from both countries would define distillation and model evaluation in technical language, so the next accusation arrives with evidence attached.
The argument that no common ground exists was refuted a week ago. At Chapel Hill, all twenty G20 members endorsed the Carolina Principles , an American-drafted framework urging governments to hold back on new AI regulation. China signed. The United States and China could reach agreement on mutual constraints.
China absorbs cyberattacks, carries the same runaway-agent exposure in its own deployments, and has no appetite for an open-ended race it must fund indefinitely. Accords hold because they track interests, not because the signatories trust one another. Should the American delegation arrive with a charge sheet, it will collect a communiqué praising the value of dialogue and nothing operational. The first serious AI-driven incident between the two countries would then be handled by guesswork on both sides. The alternative costs nothing more than showing up without the sermon.
The post U.S.-China AI Security Talks Need Shared Rules Not Grievances appeared first on Foreign Policy In Focus .
U.S.-China AI Security Talks Need Shared Rules Not Grievances
Aggregated summary from an independent source. Read the original at FPIP.