On September 4, 2026, Reuters reported that the US and China are preparing for their first official bilateral talks focused exclusively on AI safety, tentatively planned for mid-September. Washington wants the US-China talks to address AI-directed cyberattacks and has proposed cooperation between US and Chinese AI laboratories to monitor and share information about such threats. The proposed dialogue comes days after cybersecurity researchers and OpenAI reported that 700 rogue AI agents had attacked the AI startup Hugging Face in July and attempted to conceal it.
Both states hold data centres and headquarters for OpenAI and Anthropic. These developments point to a problem neither Washington nor Beijing can address through technological competition alone. Now, AI is moving from a tool used by cyber operators to a potential actor capable of carrying out complex operations with limited human interference. In current times, the US and China are competing extensively for leadership in advanced AI. The danger is therefore not simply that AI will make cyberattacks more powerful, but also that the strategic competition could encourage both powers to develop offensive AI capabilities faster than they develop mechanisms to control them.

The upcoming dialogue consequently presents a narrow but crucial opportunity. Washington and Beijing do not need to resolve their broader technical rivalry. They need to prevent that rivalry from producing a cybersecurity dilemma in which increasingly autonomous systems, uncertain attributions, and compressed decision-making make escalations harder to control.
If AI systems start launching cyberattacks with less human intervention, it may become difficult to know who launched the attack, which leads governments to have very little window to understand what happened before making a decision on how to respond. It can turn a small cyber incident into a larger conflict.
Yet, expecting the US-China AI talks to produce meaningful constraints on AI-enabled cyber operations may be overly optimistic. The fundamental obstacle is not a lack of awareness about the risks, but the strategic value of the capabilities involved. For Washington and Beijing, the increasing use of AI is connected to economic competitiveness, military efficiency and national security. Neither side has the incentives to show the capabilities, vulnerabilities, and limitations of the systems that could provide an advantage over the other.
Also, there is a legitimate concern that information sharing could create a security paradox. Greater transparency about how one country detects or defends against AI-enabled cyber operations could provide the country with valuable intelligence about its defensive structures. Similarly, agreeing to restrictions on autonomous cyber capabilities could become problematic if one side agrees, but the other side continues developing such systems in secret. From this point of view, cooperation without verification could weaken deterrence rather than strengthen stability.
This scepticism is particularly relevant because the US and China do not approach technological security from identical strategic positions. Washington is concerned about maintaining its technological edge and preventing advanced capabilities from being used against American interests, while Beijing has its own incentives to reduce dependence on foreign technology and strengthen its strategic autonomy. Their broader disputes over semiconductors, technology controls and military competition make it difficult to separate AI safety from larger rivalry.
These constraints, however, do not make cooperation irrelevant. They change what cooperation should realistically seek to achieve.
The objective should not be a comprehensive agreement requiring either side to disclose sensitive AI capabilities or abandon offensive cyber research. Such an agreement would be difficult to negotiate and even harder to verify. A more practical approach would focus on reducing the consequences of miscalculation.
This distinction matters because strategic stability does not always require trust. During periods of intense rivalry, states can still establish mechanisms designed to prevent an incident from escalating beyond their control. The same logic can apply to AI-enabled cyber operations.
The first priority should therefore be a direct communication mechanism for serious AI-related cyber incidents. If an attack against critical infrastructure occurs, the ability to communicate rapidly could give both governments time to establish attribution before assuming that the incident represents any state’s action. This would not prevent either country from responding to genuine aggression: it would reduce the risk of a response based on incomplete information.
The second priority should be the human control over high-impact autonomous cyber operations. The issue is not whether AI should be allowed to assist cybersecurity. It already does and increasingly does so. The most important question is whether an autonomous system should be permitted to independently initiate actions capable of significant disruption beyond the original target.
The best outcome of this proposed dialogue is that Washington and Beijing should build a legal framework on a few principles: communication, transparency about threats, and human control. Communication can simply make transparency easier, can reduce miscalculations, and help both states identify the threats as AI-enabled. Even though all these measures don’t eliminate the threat of AI cyberwar or attack. Nor does it eliminate the current rivalry between China and the US. But it can shape the way of rivalry between the states.
The upcoming dialogue should be able to open a window for both states before this problem becomes a crisis. The question is simple: whether the US and China can develop restraint to ensure that an AI-directed cyber race does not take the place of human ability to control.
If you want to submit your articles and/or research papers, please visit the Submissions page.
To stay updated with the latest jobs, CSS news, internships, scholarships, and current affairs articles, join our Community Forum!
The views and opinions expressed in this article/paper are the author’s own and do not necessarily reflect the editorial position of Paradigm Shift.
Abraiz Ali Ahmad is an international relations student at the University of Gujrat, with a strong interest in regional security, geopolitics, and connectivity. He enjoys looking beyond official statements and headlines to understand the interests, vulnerabilities, and consequences shaping regional developments. His particular areas of interest include South Asia, Central Asia, and the Middle East, especially where conflict, infrastructure, and geopolitics intersect.






