Loading questions
Loading questions
Generated Sep 18, 2026, 4:09 PM
Conditional on the September 24 meeting taking place, I put YES at 23%. The live path is a narrow cyber-incident or non-state-actor information-sharing mechanism, not a broad AI arms-control deal (Reuters, September 4). NO is favored because the AI track has made little progress, was folded into a crowded economic session, and must produce operational detail beyond May’s existing dialogue and protocol promise (AP, September 17, SCMP, September 12, CNBC transcript, May 14).
AI is a real summit workstream. Treasury Secretary Scott Bessent says the United States is open to discussing shared risks and both open- and closed-weight models. He and Vice Premier He Lifeng are due to hold multi-hour talks in New York covering AI, trade, rare earths, and other economic issues, with possible working-level follow-up on Monday (Axios, September 16).
The threshold is much higher than getting AI into the summit communiqué. In May, Bessent said the two governments would set up a protocol to keep powerful models away from non-state actors, while China’s official account confirmed an intergovernmental AI dialogue rather than an operating arrangement (CNBC transcript, May 14, China State Council, May 19). September language must therefore add a real procedure, restraint, reporting channel, or other operational feature.
The narrow historical record points to a minority probability. I use five official U.S.-China AI engagements from November 2023 through May 2026, plus the closest earlier cyber-risk analogue. The AI-only class has one clear qualifying-style success in five cases, or 20%. Adding the 2015 cyber agreement gives two in six, or 33%. The sample is tiny and selected for relevance, so it is an anchor rather than a statistical estimate.
| Date and engagement | Public outcome | Classification under this question’s standard |
|---|---|---|
| September 2015, Obama–Xi cyber agreement | Timely responses to cyber-assistance requests, investigative updates, a restraint on commercial cyber theft, a high-level dialogue, and a hotline | YES analogue |
| November 2023, Woodside | Agreement to convene experts on advanced-AI risk and safety | NO: dialogue only |
| May 2024, Geneva AI dialogue | Exchange of national views on AI risks and governance | NO |
| November 2024, Lima | Human control over decisions to use nuclear weapons | YES at the time; now in the baseline |
| October 2025, Busan | Calls for dialogue and mutually beneficial AI cooperation | NO |
| May 2026, Beijing | Intergovernmental dialogue plus Bessent’s public intent to develop a non-state-actor protocol | NO, though borderline as a precursor |
The strongest positive evidence is unusually concrete. Reuters reported that Washington had proposed monitoring AI-directed cyberattacks and asking American and Chinese laboratories to share information aimed at preventing AI-linked attacks. The same report said Chinese officials viewed AI talks as a potential major summit deliverable, although the agenda and participants were still unsettled (Reuters, September 4). The Bessent–He talks give negotiators a final route to turn that idea into leaders-ready language (Axios, September 16).
Both governments also have domestic policies compatible with a narrow cyber mechanism. Trump’s June executive order created a voluntary AI cybersecurity clearinghouse and classified frontier-model cyber benchmarking, while the resulting GOLD EAGLE program coordinates vulnerability discovery and remediation among government and industry (White House executive order, June 2, White House GOLD EAGLE release, July 14). Xi called in July for technical monitoring, early warning, emergency response, prevention of malicious use, and continued human control; China released an updated AI Safety Governance Framework on September 14 (Xi’s July speech, CAC Framework 3.0). This is real policy overlap, especially on cyber incidents and non-state actors.
The process evidence still points down. AP reported that little progress had followed the May dialogue mandate (AP, September 17). SCMP reported that the AI track had been folded into the wider economic meeting and that only the Board of Trade was expected to yield a summit deliverable; its sources still saw AI security as the area with the most overlap (SCMP, September 12). These are anonymous-source reports, but they address the key question: whether usable text is mature, not merely whether AI will be discussed.
The political constraints are also severe. Trump has called catastrophic AI warnings a hoax and framed extra guardrails as helping China, though he has left room for some regulation and cyber protection (AP, September 14). China rejected U.S. accusations of industrial-scale model distillation as technological containment and threatened countermeasures, while still supporting professional dialogue (MOFCOM, September 9). In February, both governments declined to endorse a nonbinding 20-principle declaration on responsible military AI, making a new military restraint much less likely than a cyber contact mechanism (Reuters, February 5).
My main stage-gate model assigns a 27% chance that negotiators produce specific, mutually acceptable text in time. If such text exists, I assign an 80% chance that the leaders approve it and an official account describes it clearly enough. Without prepared text, I assign a 2% chance of a qualifying leader-driven surprise. That gives:
A separate mutually exclusive pathway model gives 21%: about 11% for a government cyber-notification or consultation mechanism, 6% for lab or non-state-actor information sharing, 3% for a military or human-control extension, and 1% for testing or another measure. An adjusted historical model gives 22%, while an actor-incentive model reaches 30% because a voluntary cyber mechanism is cheap for both leaders. Weighting those models produces 0.22977, reported as 0.2298.
The May protocol promise is a double-edged signal. It proves that Trump and senior U.S. officials already saw a narrow non-state-actor arrangement as politically acceptable. But it also means that announcing “a protocol” again may resolve NO unless the governments specify what they will do, who will communicate, or what incidents trigger action (CNBC transcript, May 14).
Trump’s rejection of broad AI guardrails does not eliminate the best YES pathway. His administration has already built an operational, voluntary AI-cyber system at home. A bilateral measure sold as critical-infrastructure defense, anti-terrorism, or crisis communication fits his policy better than anything described as slowing AI development (White House, June 2).
Hover a data point to trace its series, or click to view the forecast generated at that time.
Signed forecast receipt
Signed Sep 18, 2026, 4:09 PM with ed25519 key preseen-prod-ed25519-20260523 and externally timestamped Sep 18, 2026, 4:09 PM.
sha256:a7bd413993fea1...b67f9d323a