The United States has proposed that China establish a notification mechanism for artificial-intelligence incidents that could affect national security. The idea was discussed during talks in New York between US Treasury Secretary Scott Bessent and Chinese Vice Premier He Lifeng ahead of a meeting between Donald Trump and Xi Jinping.
An “AI hotline” has not yet been created. No bilateral agreement, incident definition, reporting deadline or list of responsible authorities has been published. The US has made a proposal, but China has not publicly accepted it. It is therefore more accurate to describe an emerging consultation mechanism than an operational security system.
What was discussed in New York?
The talks between US and Chinese economic officials lasted approximately eight hours. After the meeting, Bessent said the world’s leading AI powers needed greater transparency and a shared view of threats.
The US proposal would provide for mutual notification of AI incidents reaching a national-security threshold. Future dialogue is expected to address the use of AI in weapons, protection of critical infrastructure, cyberattacks and other scenarios in which an error, malicious use or misunderstood activity could have wider consequences.
US Trade Representative Jamieson Greer also took part. Alongside AI, the parties discussed trade, tariffs and critical raw materials. No new breakthrough on supplies of rare-earth minerals and magnets was announced.
Why is it being compared to a hotline?
The term “hotline” is a media and analytical comparison, not the published official name of the mechanism. The concept is to create a direct communication channel for situations in which one state detects a serious AI incident that could affect the other or be misinterpreted as a deliberate attack.
Such a channel could help distinguish a technical failure from state-authorised action, warn of an uncontrolled cyber incident and reduce escalation risk. These remain possible objectives, however. It is not publicly known what information would have to be disclosed, how quickly notification would occur or how either side would verify a report.
What AI incidents might reach the national-security level?
No precise threshold has been set. Based on information currently available, the discussion could cover scenarios such as:
- use of AI in military decision-making or autonomous weapons;
- a large-scale attack on electricity, communications, finance, transport or other critical infrastructure;
- an AI-assisted cyberattack spreading across national borders;
- bypassing model safeguards to produce high-risk biological, chemical or cyberattack information;
- uncontrolled or unintended action by an AI agent with material effects beyond one organisation;
- an incident that another state could misinterpret as an intentional intelligence, sabotage or military operation.
This does not mean every example is already included in a draft mechanism. They describe the risk categories associated in public discussion with future US–China AI safety talks.
Why will an agreement be difficult?
For the mechanism to work, the two countries must agree on at least four issues: what constitutes a reportable incident, which authority sends the notice, what information is disclosed and how to prevent the security channel from being used for intelligence gathering or political pressure.
Trust is low. The US restricts exports of advanced chips and technology to China, the countries compete over AI models, data centres and supply chains, and both Beijing and Washington regularly describe the other’s technology policy as a national-security risk.
There is also a practical problem: a government may be unwilling to disclose an incident that exposes vulnerabilities in military, intelligence or critical-infrastructure systems. Overly broad reporting could expose sensitive information, while an overly narrow threshold would make the mechanism ineffective.
What does this mean for European and Latvian businesses?
The proposal creates no new legal obligation for Latvian companies. It does indicate a broader direction: a serious AI incident is no longer viewed solely as a software error, personal-data breach or cybersecurity problem. In some circumstances, it may become an issue of critical infrastructure, supply chains and national security.
European businesses already need to assess AI risk alongside other regulatory frameworks. The AI Act provides for serious-incident reporting by relevant providers and deployers of high-risk systems when the applicable requirements take effect. In financial services, DORA governs major ICT incidents and third-party risk, while cybersecurity legislation imposes incident-reporting obligations on essential and important entities.
An international US–China mechanism would not replace those rules. It would operate at an interstate level. The information reaching that level, however, may originate with private companies such as cloud providers, AI developers, data centres, telecom operators, banks, energy companies and transport operators.
How could contracts with AI and cloud providers change?
A company cannot report an incident effectively if its supplier fails to notify it or refuses access to technical logs. AI risk management is therefore moving from general privacy language toward specific contractual obligations.
Where AI supports an important business process, the contract should address:
- the supplier’s duty to notify the customer promptly of a security incident or material model deviation;
- access to initial incident information, technical logs and investigation findings;
- allocation of responsibility between the model developer, integrator, cloud provider and deployer;
- data-location, subcontractor and cross-border data-flow information;
- the right to suspend or isolate the system without a disproportionate penalty;
- fallback arrangements, data export and service-recovery objectives;
- the supplier’s obligation to cooperate with the company and competent authorities during an investigation.
Rare earths show that AI risk is not only about software
Critical raw materials were discussed alongside AI in New York, but no new progress on rare-earth supplies was announced. The parallel matters to businesses: AI infrastructure depends not only on models and data, but also on chips, servers, electricity, cooling, communications equipment and mineral supply chains.
Even a perfect incident-communication mechanism would not resolve export restrictions, shortages or geopolitical dependencies. Business-continuity planning for AI should cover cyber incidents, cloud outages, chip availability, power supply and the location of critical suppliers.
A practical AI incident-readiness checklist
- Create an AI systems register. Record the owner, supplier, data, integrations and business process affected.
- Define incident categories. Distinguish an incorrect output, data leak, unauthorised access, safeguard bypass and an incident with critical physical or societal impact.
- Set escalation thresholds. Staff should know when an issue remains with IT support and when management, security, data protection or a public authority must be involved.
- Preserve evidence. Retain inputs, outputs, model versions, system actions, access records and administrative changes.
- Test shutdown and fallback procedures. A critical process must be able to continue safely without the affected AI system.
- Review supplier contracts. Notification deadlines, data access and investigative cooperation should be explicit.
- Run an incident exercise. Simulate an AI system taking unintended action or a provider disclosing that a model has been compromised.
The bottom line
The US proposal is not yet an international agreement and should not be presented as an operational Washington–Beijing “red phone”. The subject itself is nevertheless significant: the world’s leading AI powers are beginning to consider how to prevent a technical failure, cyberattack or uncontrolled system from being mistaken for deliberate state aggression.
For businesses, the practical conclusion is that an AI incident plan should be as concrete as cybersecurity, data-protection and business-continuity plans. The issue is no longer merely whether a model produces a wrong answer, but whether the company can detect, stop, document and explain an incident with wider consequences.
Comments
No comments yet. Yours could be the first!
Add a comment