The Window Before the Workarounds: Why U.S.–China AI Cooperation Can Succeed Where Trade Could Not

Runner Up for the China Focus Essay Contest Jimmy Carter Prize
55273364128 15400fe16b O 2048x1228

A Taiwanese newspaper reports on Presidents Trump and Xi’s May 2026 summit in Beijing. Source.

In November 2024, at their final bilateral meeting as counterparts, Joe Biden stood beside Xi Jinping in Lima, Peru, and reached a narrow agreement: The decision to use a nuclear weapon should be made by a human being and not by artificial intelligence. [1] The joint statement was both brief and non-binding, and easy to dismiss as diplomatic choreography. Yet it was also more than the two governments had agreed on any other shared problem in fifteen years.

Building on that agreement will require learning from the failures of the last decade, in which both Republican and Democratic administrations tried to pull American firms out of China through tariffs and export controls only to watch most firms reroute rather than retreat. The obstacle was not a lack of political will but a private economy whose own interests made the distance between the policy and its target impossible to close.

This essay argues that artificial intelligence is the rare domain in which the policy and the target have not yet separated. The population of relevant actors in both countries is still small and state-adjacent. No dense network of subsidiaries, joint ventures, or export routes has formed around model training the way it formed around container shipping. A rule negotiated now will bind, whereas in five years, it may not. What follows is a sketch of what that rule should look like, how it can be built, and why the window to build it is narrower than the pace of current diplomacy suggests.

A Mismatch of Means

William Norris, an expert on economic and national security at Texas A&M University, explains that states do not transact, they incentivize the firms that do. [2] Tariffs and sanctions are forms of what he calls transactional leverage, a narrow category of economic statecraft whose effectiveness rests on three conditions. The first is meaningful asymmetry in the bilateral relationship, where the state imposing the control  needs the sanctioned industry or product  less than the target does. The second is inelasticity in the good or service at stake, since leverage disappears the moment the target can buy the same thing somewhere else for a similar price. The third is proportionality between the demand and the issue at stake. No amount of economic pain will move a state off an interest it treats as existential, so the concession has to be small enough that the target can afford to give it. The last decade of economic statecraft from both Presidents Biden and Trump has met none of these conditions.

Firstly, the relationship between Washington and Beijing was anything but asymmetric. A wealthier and more educated China has meant a broader consumer base with deeper pockets to spend on things like consumer electronics. U.S. chipmakers such as Intel, Broadcom, Qualcomm, and Marvell Technology all generated more revenue from China than from the United States. [3] The Semiconductor Industry Association, which represents 99 percent of the U.S. chip industry by revenue, publicly warned that export controls risked “harming the U.S. semiconductor ecosystem without advancing national security.” [4] Beijing’s leverage is also more than just a large market, as was shown last year when China placed export controls of its own on rare earth minerals—of which it controls roughly 70 percent of the global supply. [5] Washington was picking a fight with a trading partner that could and would hit back.

The leverage problem ran deeper than mutual dependence. Even where tariffs did raise the cost of Chinese goods, the supply chains proved flexible enough to absorb the shock and reroute around it. From 2017 to 2024, China’s share of U.S. direct imports fell by eight percentage points, but total U.S. merchandise imports kept rising as firms shifted sourcing to Vietnam, Mexico, and Taiwan. [6] The pattern was not limited to American firms. Between 2012 and 2022, 81 percent of Japanese multinationals operating in China adopted at least one de-risking strategy, but only 18 to 20 percent actually decoupled. In fact, 43 percent simply expanded operations elsewhere while leaving their Chinese footprint intact. [7] What governments called de-risking became, in practice, diversification.

Finally, the scale of the demand implicit in American export controls and tariffs was always going to be unacceptable for China. Since 2020, self-sufficiency in advanced manufacturing has been a national goal for the Chinese Communist Party. [8] The export controls imposed under the Biden administration only served to further cement in the minds of Chinese officials the importance of not relying on any other power in any sector critical to national security. [9] Even as confronting Beijing has become a rare point of bipartisan agreement in Washington, it is only one of myriad domestic and foreign policy issues on any given day. For China, the choice was between accepting indefinite American dominance over advanced consumer and military technology and pursuing self-sufficiency. Beijing chose the latter, and the narrative of a China that refuses to bow to foreign powers gave the policy both deep domestic legitimacy and political importance.

The past ten years have shown that it is not that Washington lacks resolve in attempting to assert its influence on American firms and Chinese capabilities. Instead, it is that economic statecraft itself is not an effective tool in disciplining an economy when the underlying commercial and domestic linkages are already entrenched. Tariffs and export controls arrived too late. The question, then, is whether there are domains where the same mistake has not yet been made—where the relevant actors are still few enough and the governance architecture still thin enough, that a rule written today would actually hold. Artificial intelligence is one such domain, but not for long.

A Smaller Room, For Now

Artificial intelligence, as a regulatory target, looks almost nothing like the manufacturing sector in the 2010s. The relevant observation is not that the technology is novel or that its risks are new, but that the set of actors is small. There are only a handful of American laboratories—OpenAI, Anthropic, and Google—that account for most frontier training runs. [10] In China, the comparable set is similarly short: Baidu, Alibaba, ByteDance, DeepSeek, Moonshot, and Zhipu. The compute, chips, and model weights at the true frontier sit inside perhaps two dozen organizations across the two countries. Each of them is closely tied to, and in several cases financially dependent on, the state.

This is not the group that overwhelmed U.S. export controls on Chinese goods in 2019. That population had 50,000 exporters and a decentralized logistics system behind it. If Washington and Beijing want to coordinate on, say, third-party auditing of training runs above a given compute threshold, they are in essence talking to twenty laboratories whose chief executives can be summoned by name.

The institutional infrastructure is also, importantly, early enough to be movable. The U.S. AI Safety Institute (since renamed the Center for AI Standards and Innovation), housed at the National Institute of Standards and Technology, opened in late 2023. Its Chinese counterpart, the China AI Safety and Development Association, was announced in 2024. [11] ISO/IEC JTC 1/SC 42, a joint international AI standards committee, is still drafting the first generation of interoperable specifications. [12] There is no dense ecosystem of Chinese AI subsidiaries operating across the United States, nor of American ones operating in mainland China. Yet the rapid deterioration of U.S.-China relations has created an environment where frontier labs on both sides are massively discouraged from integrating or expanding into the opposite market.

The incentives for addressing a narrow but important set of risks also run in parallel. Both governments have signaled concern about loss-of-control scenarios in general-purpose AI as models become integrated into civilian and defense systems and processes. [13] China issued as many national AI safety standards in the first half of 2025 as in the previous three years combined. [11] Even as the Trump administration has avoided passing federal AI legislation and pressured state governments to do the same [14], there is still considerable agreement among the leading labs on safety and alignment standards. The three major U.S. labs all publish some publicly available evaluation of whether new models can materially be used for dangerous tasks, such as cyberattacks or developing bioweapons. [15]

While there is no uniform standard of public engagement in China, the leading AI labs have all signed a voluntary pledge with similar promises. [11] The Chinese technical community, on the questions that matter most for catastrophic risk, shares more of the American safety community’s vocabulary than the current political relationship would suggest.

These areas of shared concern do not resolve the harder questions of if and how AI should be used in civilian surveillance and military operations. To be sure, there will be areas where China and the United States disagree sharply and irreconcilably. Cooperation on AI, in the sense this essay means, is not a peace treaty. It is the narrower proposition that on the subset of AI risks governed by shared exposure rather than opposing ideology, the small number of actors and immaturity of the governance infrastructure makes coordination tractable in a way that trade no longer is.

Scaffolding, Not Summits

Just because the opportunity for engagement exists does not mean that it will last forever, or that compromises that do arise will be as resilient as the technology demands. Before policymakers in both capitals talk of a grand bargain, they must first build a set of tailored mechanisms that can succeed where the trade war’s tools failed. The same three conditions Norris identifies for effective economic coercion—asymmetry, inelasticity, and proportionality—did not hold in recent U.S.–China trade disputes. Yet in AI safety, where both sides now face a shared risk rather than opposing demands, that same logic can be turned toward cooperation rather than compellence.

The first condition that doomed tariffs was the lack of asymmetry, as both sides dug in believing the other was about to blink. In AI safety, that symmetry is an advantage rather than a liability. Neither government benefits from a catastrophic AI failure on the other’s soil, and neither benefits from an AI system deciding to launch a nuclear weapon. This basic acknowledgment is what allowed for that small but important step between Biden and Xi in Lima. Now, both sides must transform that acknowledgment into action. Such action should come from the creation of a working-level notification channel, analogous to the crisis hotlines built between the Pentagon and the Soviet General Staff in the 1960s, for incidents involving AI-integrated command systems. [16] Where mutual dependence made tariffs self-defeating, mutual vulnerability makes a notification channel self-enforcing and requires only one empowered official on each side to enact. [17]

Tariffs were uniquely vulnerable to firms covertly routing their goods and, in effect, weakening the power of the state to organize policy. The safety standards needed for AI development are not. If American and Chinese engineers agree, through ISO/IEC JTC 1/SC 42, on how to measure dangerous capabilities in a frontier model, no firm can transship its way around the specification. SC 42 is already the venue where engineers from both countries draft standards for model risk management, and it offers the foundation for future collaboration. The commercial aviation industry’s safety record was built in exactly this way. [18] Technicians agreed on how to measure something before governments agreed on what to do about the measurements. Deepening that work on emerging sub-committees for frontier-model evaluation is cooperation that helps to build trust between American and Chinese labs while giving an immediate material resource for officials and the public.

Cooperation on AI requires something far more precise than Washington’s attempt to use economic pressure to hamper China’s technological development, which Beijing regards as central to regime legitimacy. By building on the joint consensus from the 2024 International Dialogues on AI Safety hosted in Beijing and attended by leading members of American and Chinese AI development, both nations can establish some shared, modest, and non-intrusive red lines. [19] First, no AI system should be able to iterate on itself without express human approval and oversight. Second, no AI system should help design weapons of mass destruction. Third, no AI system should be able to conduct autonomous cyberattacks. In practice, this means that before a frontier model is released, it would be tested against an agreed set of dangerous capability benchmarks built on these three red lines. What counts as ‘iteration,’ ‘help,’ and ‘autonomous’ can, and should, be decided jointly by both the Center for AI Standards and Innovation at NIST and China’s AI Safety and Development Association so that we have universal and specific vocabulary for such new and dangerous threats.

Before the Window Closes

The principal-agent problem that unraveled trade policy is already beginning to emerge in AI. Diverging policy priorities have resulted in the Pentagon banning the usage of Anthropic’s Claude after the company mandated certain guarantees over the terms of military AI use. [20] Meanwhile, Chinese labs are selling API access into Southeast Asian and Middle Eastern markets—ingraining themselves in diffuse systems outside the direct purview of either Washington or Beijing. [21]

Most concerning of all is the proliferation of powerful open-weight models, which can be run locally and anonymously, making them harder for firms or governments to monitor once released. [22] While not posing a direct threat now, these can rapidly become one as new models are released and older, but still capable, ones are open-sourced. This makes urgent action on AI safety critical to ensure safeguards are in place before today’s frontier models become tomorrow’s open-source systems.

These trends are the seeds of a porous network that made tariffs largely ineffective. The government-to-laboratory ratio is, briefly, still in both governments’ favor, but that will not last. What was agreed upon in Lima two years ago can remain a one-off in a relationship that continues to spiral downwards. Or it can be the start of a small but substantive recalibration—one built on shared exposure rather than shared values and on the recognition that cooperation does not require realignment. Those larger issues are for another day. But that day can only arrive if both sides act while there is still time.

References

[1] White House. (2024, November 16). “Readout of President Joe Biden’s Meeting with President Xi Jinping of the People’s Republic of China.” Lima, Peru.

[2] Norris, William J. (2025). “Security Externalities: A Firm-Centric Theoretical Framework for Economic Statecraft.” Law & Geoeconomics, 1, 175–213.

[3] CNBC. (2024, April 12). “China Remains a Crucial Market for US Chipmakers Amid Rising Tensions.”

[4] Semiconductor Industry Association. (2023, October 17). “SIA Statement on New Export Controls.”

[5] U.S. Geological Survey. (2025, January). Mineral Commodity Summaries 2025.

[6] Alfaro, Laura, and Davin Chor. (2025). “An Anatomy of the Great Reallocation in US Supply Chain Trade.” Working paper, Harvard Business School and Tuck School of Business, Dartmouth College.

[7] Cichanowicz, Timothy, Jiakun Jack Zhang, and Samantha A. Vortherms. (2025). “De-risking Without Decoupling: Japanese Multinational Responses to Geopolitical Risk in China, 2012–2022.” Working paper, University of Kansas and University of California, Irvine.

[8] Congressional Research Service. (2024, December 12). “Made in China 2025 and Industrial Policies: Issues for Congress.” IF10964.

[9] RAND. (2025, June). “Testing Self-Reliance: What the Trade War Reveals About China’s Vulnerabilities and Power.”

[10] Epoch AI. (2024, May 28). “Training Compute of Frontier AI Models Grows by 4–5x Per Year.”

[11] Concordia AI. (2025, July). State of AI Safety in China (2025). Beijing: Concordia AI.

[12] International Organization for Standardization and International Electrotechnical Commission. (n.d.). “ISO/IEC JTC 1/SC 42 — Artificial Intelligence.”

[13] Sheehan, Matt, and Scott Singer. (2025, October 16). How China Views AI Risks and What to Do About Them. Washington, DC: Carnegie Endowment for International Peace.

[14] CNN. (2025, July 1). “US Senate Votes to Strike Controversial AI Regulation Moratorium from Trump Agenda Bill.”

[15] METR. (2025, December). “Common Elements of Frontier AI Safety Policies.”

[16] NTI (Nuclear Threat Initiative). (2024). Reducing the Risks at the Intersection of AI and Nuclear Weapons. Washington, DC: NTI.

[17] The Carter Center. (2023). “Modernizing Sino-U.S. Confidence-Building Measures: Cold War Case Studies.”

[18] MacKenzie, David. (2010). ICAO: A History of the International Civil Aviation Organization. Toronto: University of Toronto Press.

[19] IDAIS (International Dialogues on AI Safety). (2024, March 10–11). “Consensus Statement on Red Lines in Artificial Intelligence.” Beijing.

[20] CNBC. (2026, April 8). “Anthropic Loses Appeals Court Bid to Temporarily Block Pentagon Blacklisting.”

[21] Taipei Times. (2026, April 12). “New DeepSeek Model to Test China’s AI Ambitions.”

[22] Bommasani, Rishi, Sayash Kapoor, Kevin Klyman, Shayne Longpre, Ashwin Ramaswami, Daniel Zhang, Marietje Schaake, Daniel E. Ho, Arvind Narayanan, and Percy Liang. (2024). “Considerations for Governing Open Foundation Models.” Science, 386(6718), 151–153.

Charlie Andrade is pursuing a Bachelor of Arts in Political Science and Global & International Studies at the University of Kansas. He is also director of communications at the University of Kansas Trade War Lab.