When U.S. Treasury Secretary Scott Bessent told CNBC on May 14 that the United States and China would establish a protocol for AI best practices and safety, the statement arrived in a context of escalating technology competition, chip controls, export restrictions, and sharp disagreement over Taiwan. The AI safety channel, if it becomes more than a diplomatic gesture, represents something unusual: a domain where both governments appear willing to discuss shared risks despite their rivalry.
“We’re going to set up a protocol in terms of how do we go forward with best practices for AI to make sure nonstate actors don’t get a hold of these models,” Bessent said, in remarks CNBC reported from the sidelines of President Trump’s two-day meetings with Xi Jinping in Beijing. “The two AI superpowers are going to start talking.”
The Logic of the Talks
Bessent’s stated focus was on nonstate actors, terrorists, criminal organizations, or other parties that might seek to access powerful AI models for harmful purposes. This frames the AI safety dialogue as a shared-risk conversation rather than a capability competition: both governments have an interest in preventing AI misuse by actors outside state control. The framing is also diplomatic cover. Bessent acknowledged the competitive dynamic directly: “The reason we are able to have wholesome discussions with the Chinese on AI is because we are in the lead.”
CNBC separately connected the summit context to questions about Anthropic’s Mythos model and AI-enabled cyberattack capabilities, suggesting the discussions extended beyond narrow model-safety questions to AI’s emerging role in security contexts.
The summit also featured an unusual signal about chips. Nvidia CEO Jensen Huang, who had not initially been part of the U.S. delegation, joined as a late addition, with reporting that he boarded Air Force One for Beijing. CNBC linked the AI talks to the context of U.S. restrictions on advanced Nvidia chip sales and reports of possible H200 chip clearances, suggesting that AI safety dialogue and AI hardware policy may be discussed in proximity even if they remain formally distinct tracks.
A Protocol, Not an Agreement
What Bessent described is a planned protocol and a process to be established, not a finalized regulatory agreement or binding commitment. The distinction matters for how the announcement should be read. Earlier reporting on whether AI safety would appear at the Trump-Xi summit noted that experts assessed deep strategic mistrust made binding commitments unlikely, while shared fears over AI misuse could sustain a dialogue channel.
If the protocol moves from announcement to implementation, it would create a limited institutional channel for AI governance conversation between the two largest AI powers at a moment when no such channel exists. The practical challenge is that both governments define AI safety partly in terms of the other country’s capabilities , the U.S. is concerned about Chinese military AI applications, and China about U.S. AI dominance and its implications for sovereignty. A protocol focused on nonstate actors may be narrow enough to avoid that tension, but it would also be narrow enough to leave the central competitive questions entirely unaddressed.
The Chip Dimension
The presence of Jensen Huang in the Trump delegation adds a commercial dimension to the safety framing. Nvidia’s business in China has been sharply constrained by export controls on advanced chips, and the company’s CEO joining the Beijing trip drew attention to the possibility that AI safety talks and AI chip policy might be discussed in parallel, even if formally distinct. CNBC reported that the context included questions about possible H200 chip clearances, a level of access that had been restricted by earlier export-control rounds.
The interplay between safety dialogue and commercial chip policy illustrates a tension inherent in the U.S.-China AI relationship. Safety talks require some degree of technical transparency between the two governments about AI capabilities. That transparency could theoretically inform export-control policy, or it could create political cover for relaxing restrictions. Both governments have incentives to manage that tension carefully, which is one reason formal safety protocols in this domain tend to be narrow and slow.
For the AI governance ecosystem, the summit’s most durable significance may be less in what was agreed than in the signal that AI has formally arrived as a bilateral diplomatic topic alongside trade, Taiwan, and chips, a status it did not hold with equivalent clarity before the Beijing meetings. China’s own regulatory trajectory points toward a comprehensive domestic AI law, which could eventually create either a compatibility surface or a new source of friction with whatever international frameworks emerge.
