AI is already breaking out of the lab. Trump’s red phone won’t stop it

.

Six U.S. corporations at the forefront of artificial intelligence signed an accord this week called the “Joint Commitment on Frontier Responsibilities.” It is neither a contract nor law, but a voluntary agreement that President Donald Trump calls “morally binding.” The United States now has a foundation for an emerging domestic AI safety architecture. But we must also remain focused on establishing an international system to mitigate cross-border AI frontier threats.

The American corporate AI accord was signed on Sept. 29, five days after Chinese President Xi Jinping visited Washington for a U.S.-China summit in which AI was prominently featured. The moment was historically significant. If the U.S.-China rivalry is becoming or has become a second Cold War, AI is emerging as its defining technology, as well as an industrial revolution of its own. Yet the summit produced only a modest first step toward managing that transformation: the U.S. and China agreed to establish a communication channel dedicated to AI-related incidents.

The idea resembles the Cold War “red phone” between Washington and Moscow for avoiding nuclear war. But frontier AI crises in the 21st century are materially different enough from nuclear crises in the 20th century to render a red phone entirely insufficient. A red phone establishes whom to call and how to reach them, but not when to call, what constitutes a crisis, what information must be communicated, or what happens afterward. And unlike the nuclear confrontation between two governments, frontier AI risks can involve private companies, nonstate actors, and autonomous AI agents. The analogy of the U.S.-Soviet nuclear weapons race therefore has limits when applied to the current U.S.-China AI race.

When U.S. and Chinese officials continue their AI dialogue in Shenzhen, expected to be in November, they must go beyond the red phone. The two superpowers should begin building a shared architecture of common definitions, risk thresholds, independent evaluation, and predetermined responses that can ultimately be adopted by other major AI powers.

The need for such an architecture is growing more urgent as AI becomes more deeply integrated. China has set ambitious targets for embedding AI across industry, science, government, and society at large. Meanwhile, controlled evaluations of agents powered by American and Chinese AI models have documented deceptive behavior, evasion of restrictions, and other undesirable autonomous actions.

This includes the OpenAI-Hugging Face incident in July, when experimental AI agents circumvented controls designed to isolate them from the internet, found ways to secretly communicate and cooperate with one another through unauthorized channels, and ultimately hacked and compromised parts of Hugging Face’s systems, all during a cybersecurity evaluation task. OpenAI later said the agents’ actions were “misaligned with the goals of their assigned tasks,” and that the incident was a “warning shot.” Fast forward to this week, Anthropic’s initial public offering filing reportedly discloses to investors that frontier AI could present “catastrophic or existential risks to humanity.”

The danger is not limited to AI escaping human control. RAND researchers Jim Mitre and Joel Predd have warned that uncertainty over a rival’s progress toward artificial general intelligence could itself produce instability through miscalculation, preemption, or fears of a first-mover advantage. Governments therefore must anticipate dangerous international dynamics as well as dangerous AI capabilities and prepare contingency responses before they emerge.

International crisis management is therefore crucial to AI safety. AI looks like a modern Tower of Babel, another creative and perhaps hubristic attempt by humanity to reach as high as divinity. And avoiding Babel’s fate may require establishing precisely what its builders lost: a common language.

A red phone between Washington and Beijing will be of little use if officials on either end do not share definitions of an AI “incident,” “dangerous capability,” or “loss of control.”

Fortunately, they need not invent that language from scratch. The Organization for Economic Co-operation and Development has developed a 29-criterion framework for reporting AI incidents and hazards. The U.S. and Chinese governments should use it as a starting point for determining which incidents require notification, how they are classified, and what information must be exchanged.

They should also develop common methods for evaluating frontier AI systems for catastrophic biological, cyber, and loss-of-control capabilities, subject to credible independent oversight. The new American corporate accord similarly requires independent external audits of companies’ internal safety controls. Internationalizing that principle would give governments greater confidence in the credibility of evaluations conducted abroad.

Most importantly, the U.S. and China must agree in advance on responses when dangerous thresholds are crossed in either country. Several frontier AI companies already use versions of this approach, tying predetermined safeguards to capability thresholds. An international framework could similarly establish escalating safety requirements for additional testing, heightened security, deployment restrictions, notification, and, in extreme cases, temporary nondeployment.

Washington and Beijing do not need to agree on whether the AI race should accelerate or slow down. Nor must they share model weights, source code, commercial secrets, or sensitive military information. They instead need to agree on the rules that apply when the AI race goes wrong. Cooperation can remain narrowly focused on catastrophic risks capable of crossing borders, escaping human control, or provoking dangerous miscalculation.

Eventually, other major AI powers should join this architecture. The goal should not be global AI government, but global AI crisis interoperability. Countries can have different regulations at home while maintaining compatible definitions, evaluation standards, and emergency procedures. Unlike intelligence interoperability among allies, this system would have to function among adversaries. But its purpose would not be mutual trust, only limited cooperation stemming from mutual interests, despite mutual distrust.

POLITICIANS WANT TO POLICE ‘DEEPFAKES’ TO CONTROL THE TRUTH. THE FIRST AMENDMENT SAYS NO

The red phone is therefore a worthwhile start, but the coming talks in Shenzhen should be about building the system around it. Before the phone rings, Washington, Beijing, and eventually other AI powers must already have common language and practices in response to AI incidents.

If the world’s two AI superpowers do not create an international system for dealing with AI crises, having a U.S.-China red phone and a nonbinding accord between American corporations will each be of little benefit. Given its rapid advancement, the danger of frontier AI is not merely a distant dilemma for future generations, nor can it be solved simply through open bilateral communication. The warning signs are already here. The international architecture for AI crisis response must exist before the crises arrive.

Jeremy Etelson is a recent op-ed contributor to the Washington Examiner, has written political commentary for the Hill, and has appeared on Fox Business and NewsNation discussing national politics. He previously worked in congressional and Maryland politics and served as a judicial law clerk on the Circuit Court for Montgomery County, Maryland. He holds a J.D. from George Washington University Law School and an M.Phil. from the University of Cambridge.

Related Content