Last week, ahead of the U.S. and China meetings, I published a new CAP report with my colleagues from the National Security and International Policy team, “The U.S. and China Must Explore Pacing the Frontier During September AI Dialogue.”
There’s a lot in the report, including five stretch but potential deliverables for the meeting if both countries want to discuss pacing the frontier and potential AI loss of control concerns, so I obviously encourage you to check it out.
But I wanted to focus on one part of the report that focuses on a CCTV post that I first noticed when Bill Bishop at Sinocism first flagged and translate it (and Geopolitechs also translated it). But Bill Bishop also wrote “This suggestion seems unworkable given the US government can’t even get its watered-down EO done.”
When I read this, that’s not actually what I saw, but that’s understandable as there ar not a lot of China experts who also track the day-to-day of U.S. domestic AI regulation, and honestly almost no one is paying attention to the Trump secret de facto licensing system.
When I read the CCTV post’s second principle, I couldn’t quite tell if the section was written by someone who who was attempting write what sounded like significant demands from the U.S. or if it was written by someone clever who understood that these demands sounded significant but in reality the U.S. had actually already done, or not done in the case of restricting Chinese AI models, or was likely to do in the near future almost all of the things demands. I suspect it was the former but who knows?
We touched on this some in our CAP report but I wanted to break down my thinking with with additional details and commentary, starting here (block quotes below are quoting from my own report):
At the same time that Office of Science and Technology Policy Director Michael Kratsios was introducing the aforementioned Carolina Principles at the G20 ministerial, a China Central Television (CCTV) post (translation from Geopolitechs), widely viewed as signaling Chinese conditions for the September talks, attacked U.S. frontier AI company Anthropic.
The majority of the post is a screed against Anthropic and its co-founder Dario Amondei, who has long publicly held that China above all else should not be allowed to achieve transformative AI due to the danger of digital authoritarianism (and who became even less popular with the Chinese a few weeks later when he posted his “We Must Pace the Frontier” essay).
This attack on possibly the fast growing U.S. company in history which is set to IPO could seem like a significant attack on a superstar American company but Anthropic has spent most of 2026 having drawn the wrath of the Trump administration. From the Secretary of War’s attempt to execute the entire company by attempting to assert a Supply Chain Risk designation using authorities he did not have to the administration slapping export controls on their Mythos and Fable models forcing them to withdraw them from the public, it is hard to say at any given moment if the Trump administration considers Anthropic a friend or an enemy.
So the attacks on Anthropic could be one part legitimate anger and one part an attempt to let the Trump administration know they could have a common enemy.
What is more important, and what we will get to below, are the two principles for discussion, the first of which is:
[The post] laid out two principles for discussion with the United States on AI starting with “a distinction between what constitutes a genuine security threat and what is merely technological competition.” There are numerous ways to interpret this; the Chinese have many different definitions of “loss of control” as Zilan Qian of the Oxford China Policy Lab has noted, and there will always be ways to refuse to come to agreement on a definition. But fundamentally, a narrow and mutually agreed-upon definition of “genuine security threats” is the first step to any AI security discussion of AI safety risks.
I won’t dwell too long on this part and I understand that there are numerous ways to interpret this, the Chinese could twist this, they can stall, actually mean export controls, etc. I get it. But fundamentally, if you just take this literally, these two geopolitical adversaries would obviously need to discuss and agree upon what they consider a “genuine security threats” in order to have a further discussion on how to deal with it.
I think the second principle is actually much more interesting and what I bring my expertise to examining.
The second principle seems boisterous at first read:
“Second, if the United States wants to talk about rules, it must first prove that the rules are equally effective against its own companies. Relevant figures on the American side are already discussing how to get China to agree to restrict ‘AI models with dangerous capabilities.’ The question is this: with companies like Anthropic in existence, before the United States asks China to restrict model releases and disclose risks, should it not first investigate its own companies, make public the purposes, scope, and rules of their identification mechanisms, and subject them to third-party audits?”
Starting slightly out of order with the part about the U.S. treating Chinese AI models, “Relevant figures on the American side are already discussing how to get China to agree to restrict ‘AI models with dangerous capabilities.’" I noted in the CAP report:
“After the July release of Moonshot AI’s Kimi K3 open-weight model, White House officials publicly accused Chinese AI companies of adversarial distillation and in September released a cybersecurity warning about Chinese distillation of U.S. AI models. The Trump administration reportedly considered taking action against Chinese open-weight AI models. But facing significant pushback from domestic tech companies, the United States has not yet taken steps against Chinese open-source or open-weight models and exempted them from the nonpublic “voluntary framework” ordered by the AI executive order issued June 2.
That means in the United States, Chinese AI models are subject to far fewer restrictions than American models currently under the Trump administration’s secret de facto licensing framework that exempts Chinese open-source or open-weight models.”
To double back to the beginning of the second principle, “if the United States wants to talk about rules, it must first prove that the rules are equally effective against its own companies” we wrote:
“In contrast, the United States has already restricted model releases for American AI but not for Chinese models, applying export controls to Anthropic’s release of Mythos and Fable and removing them from the market for weeks, and having OpenAI agree to a controlled release of GPT-5.6.”
Then the post says, "should it not first investigate its own companies”?
As for the CCTV post asking whether the United States “should it not first investigate its own companies,” American frontier AI labs are already under investigation as state attorneys general have opened investigations into OpenAI over the Hugging Face hack and some members of Congress are demanding hearings—though it is unclear whether the U.S. federal government will, or is, investigating OpenAI over the incident.
Really the only outlier here is that the federal government has not announced an FBI/DOJ investigation into OpenAI over Hugging Face (or any company over rogue AI agents incidents) and if one were announced ahead of the summit, that would be interesting timing.
Then the post says, “make public the purposes, scope, and rules of their identification mechanisms” and we note:
Congress and many organizations, including CAP, have demanded the administration make public its “voluntary framework,” lawsuits have been filed to compel its release, and its continued secrecy is likely unsustainable.
This week the Trump administration just agreed to make public by October 30th thanks to a lawsuit from Protect Democracy, which was also something the post demanded America do, and which I noted was likely to happen. Was the timing entirely coincidental? If you’re going to lose in court and be forced to reveal it, might as well take away a Chinese talking point with the timing of the announcement too.
“And subject them to third-party audits”:
Furthermore, Illinois law SB0315, which goes into effect in January 2027, requires independent third-party audits for frontier AI models beginning in January 2028.
There is currently only one frontier AI law in effect in the U.S., California’s SB 53, but is part of a trio of state frontier AI laws go into effect that are relatively harmonized after brutal fights between AI companies and activists, with the Illinois law requiring third-party audits starting in 2028 (and California having just passed a bill licensing Independent Verification Organizations (IVOs) and an executive order looking at embedding evaluators in frontier labs). So the U.S. will soon be subjecting its frontier AI companies to third-party audits.
Then there’s this paragraph:
“If American companies can return data without users knowing, skip permission confirmation, and enable automated decision-making by default, while the U.S. government says nothing, then American talk about “security boundaries” is empty.”
This echoes a lot of complaints about Anthropic and Claude Code in the parts above, tying this to security risks and I autonomy.
“Only after the United States proves that its safety rules are equally binding on its own model companies can China and the United States move into substantive discussion.”
Again noting above, the U.S. has a state law that governs frontier AI, a secret de facto licensing framework for U.S. frontier AI models while exempted Chinese AI models from that framework, and has slapped export controls on Anthropic models. So are these demands serious or just meant to sound serious?
Given the Trump admin AI framework will eventually be public, at this point we should keep an eye out for two things ahead of, during, or after these meetings:
The announcement of an FBI and/or DOJ investigation into a U.S. AI company for a rouge agent incident ( I suppose extra points for the Chinese if the investigation is of Anthropic).
The random trashing of Claude Code’s auto mode or a reference to “dangerously-skip-permissions” by a senior administration official or Trump.
Anyway, while not reading too much into a single post, it is interesting that the second principle articulated may seem significant at first glance but is mostly already achieved when closely examined. Guess we will find out over the next week.


