September 22, 2026
CNAS Insights | U.S.-China AI Agreements Need Verification, Not Trust
The upcoming Trump-Xi summit is likely to disappoint the leaders of top AI labs that have recently called for urgent, coordinated pacing of frontier AI progress. While agreement to cooperate on some narrow domains of AI risk might be achievable, neither the United States nor China appears prepared to pursue an ambitious AI safety agreement. Trust between Washington and Beijing is low, and this seems unlikely to change anytime soon. But high political trust may not be essential should new technologies emerge to verify compliance with future agreements, even between rivals who assume the worst of each other.
Driven by competition between labs and with China, U.S. companies have been building ever more capable systems faster than they can secure or control them. The last few months have been littered with incidents of AI systems acting in harmful ways against human intent. Speed is also coming at the cost of security, leaving companies’ valuable intellectual property vulnerable. Just this week, three researchers revealed they had breached OpenAI’s internal systems with just a few hours effort and less than $3,000. These resources pale beside those of China’s Ministry of State Security, highlighting how exposed American AI labs remain to sophisticated external actors.
While export controls on advanced chips and semiconductor manufacturing equipment have protected America’s lead in frontier AI, capabilities proliferate over time. China is building advanced AI systems of its own. An uncontrolled or misused AI can damage American interests whether it’s built in San Francisco or Shanghai. Managing this technology for the long term may eventually require some kind of agreement between the two AI superpowers.
These risks are already prompting calls for stronger international coordination. In July, roughly 1,400 AI lab employees signed an open letter calling for an international effort to develop the tools needed to pace AI development, joined by similar calls from Elon Musk, Sam Altman, and Dario Amodei. Beyond lab leaders, 69 percent of Americans favor strong AI rules even if they slow development, while just 14 percent favor holding back on regulation to help U.S. companies stay ahead of China.
An uncontrolled or misused AI can damage American interests whether it’s built in San Francisco or Shanghai.
Today the political will may be missing in both capitals. But politics can shift quickly. Both the U.S. and Chinese governments have expressed significantly greater concern about AI safety over the past year, and both Washington and Beijing have shifted their regulatory approaches in response. The establishment of a bilateral AI dialogue during Vice Premier He Lifeng and Treasury Secretary Scott Bessent’s weekend meeting suggests some room for limited cooperation, even if neither side is prepared to accept substantive constraints on AI development. More serious incidents or greater confidence in either party’s willingness to unilaterally adopt AI safety measures could shift the political calculus.
The thornier obstacle is distrust. Neither Washington nor Beijing is likely to accept the other’s promise to adhere to AI safety agreements. Former U.S. diplomats warn that China could use AI safety dialogues to “take advantage” of safety rhetoric, while “doing everything it can to get ahead.” Indeed, the United States would be unwise to blindly trust its adversary. But blind trust is not necessary.
If the stakes of AI development soon make cooperation essential, the United States and China will need agreements that don’t depend on trust. Arms control offers a precedent. When Washington and Moscow signed the SALT I and Anti-Ballistic Missile Treaty in 1972, neither trusted the other to keep its word; instead, each side counted the other’s missile silos with reconnaissance satellites as an early form of verification.
The same logic could work for AI. Verifying compliance in a future U.S.-China AI agreement could open up new deal space and make a wider agreement more credible and feasible. The robust verification infrastructure required will take years to develop, so the work should begin now.
Verification Can Make AI Agreements Possible
Verification is about giving countries sufficient confidence that their counterparts are complying with an agreement. For AI, that does not require observing every computation inside a data center or every use of an AI system. Some AI agreements may require little or no verification—for example, commitments to share information about AI risks, improve transparency, or conduct independent evaluations. Verification becomes more important when an agreement places measurable limits on AI development or compute use. For instance, the United States and China could agree not to conduct training runs above a specified compute threshold, to limit the amount of compute devoted to developing increasingly capable models, or to dedicate a specified share of compute to safety and alignment research. In these cases, verification could help establish whether each side is actually complying with the agreed limits.
Today, low-cost AI verification infrastructure does not exist at the necessary scale or maturity. But many of its building blocks do. Existing intelligence-gathering capabilities could provide one layer of verification. Satellite imagery could identify new data centers and track changes to existing ones, while financial records and physical sensors could provide evidence of compute acquisition or electricity consumption.
Deep distrust between the United States and China makes it hard for either party to open up this prized technology to foreign scrutiny. But history suggests it can be done under even the hardest of circumstances.
More precise verification mechanisms could involve software- and hardware-based approaches. For example, if the United States and China agreed not to conduct training runs above a specified compute threshold, both sides could require compute operators to report how much relevant compute they own or operate, giving independent monitors a baseline for identifying where the computing capacity capable of violating the agreement is located. Independent auditors could then use cryptographic proofs generated by those systems to verify how the compute was used. Network traffic shaping could provide another layer of verification by limiting how much information clusters of AI chips can send to one another, making large-scale training runs more difficult and expensive.
Verification cannot fully eliminate the possibility of cheating. Countries could attempt to conceal undisclosed stores of compute, while firms could obscure ownership through shell companies or other off-book arrangements. But as in arms control, verification’s purpose is not to eliminate the possibility of cheating but to make significant violations sufficiently difficult, detectable, and attributable that compliance becomes the preferable strategy. Furthermore, verification will likely depend on several complementary approaches, as no one mechanism will be wholly sufficient on its own. This will likely require layering multiple imperfect sources of information so that significant violations become increasingly difficult to conceal. This defense-in-depth approach, borrowed from cybersecurity, could make the risk of detection high enough that countries have stronger incentives to comply than to defect.
Closing these gaps will require continued investment in verification technology. Increased research and development (R&D) dedicated to verification could also expand the option space for designing verifiable AI safety agreements. With more sophisticated verification tools, future agreements could target specific dangerous activities without unnecessarily restricting beneficial AI development.
Even without an international agreement, verification R&D could prove useful. Technologies that provide greater visibility into AI compute could help governments better enforce export controls and use privacy-preserving techniques to detect misuse. Verification technology also has commercial applications, with software-based mechanisms already deployed by start-ups for domestic AI compliance and auditing needs.
Laying the Groundwork for Future Agreements
Even though the upcoming U.S.-China discussions are unlikely to produce a substantial agreement on AI safety, negotiators should nonetheless lay the groundwork for future cooperation by improving bilateral communication on AI risks. Independent of the dialogue, the U.S. government should also begin the technical work needed to verify future agreements.
The first priority should be improving communication and transparency between Washington and Beijing on AI risks. The establishment of a bilateral AI dialogue during the meeting between He Lifeng and Scott Bessent now provides a regularized channel for doing so. At their next meeting, the two governments could develop shared terminology for frontier AI systems, establish common approaches to evaluating dangerous capabilities, and create procedures for sharing information about AI risks where doing so would not reveal capability-enhancing details. They could also begin defining which serious AI incidents warrant prompt notification.
If the U.S. government decides that an international AI agreement is necessary, it will need the technical means to verify compliance. Funding verification research now would give the United States those tools when they are needed.
The field of engineers working on AI verification around the world is tiny. One estimate puts their number at around 50. The U.S. government can help expand this crucial field by funding the many promising but under-resourced research areas and open questions in AI verification.
Even modest federal investment could dramatically accelerate progress. Congress could fund a dedicated AI verification R&D program at the Defense Advanced Research Projects Agency (DARPA) or the Department of Energy’s national laboratories, which spent decades developing the sensor and inspection technologies that underpinned nuclear arms control. Government funding should also extend beyond traditional grants. For instance, DARPA or the National Science Foundation could offer philanthropically-funded “bounties” for solving open problems in the technical verification space or supply hardware testbeds for prototyping of various on-chip mechanism designs.
Conclusion
Creating a verified, international AI agreement will undoubtedly be difficult. Deep distrust between the United States and China makes it hard for either party to open up this prized technology to foreign scrutiny. But history suggests it can be done under even the hardest of circumstances. Throughout the Cold War, verification did not resolve strategic competition between the United States and Soviet Union. It made selective cooperation possible despite mutual distrust. AI’s collective action problems may require the same. The technologies and institutions that make verification work take years to build. The work has to start now.
Ruby Scanlon is a research associate with the Technology and National Security Program at the Center for a New American Security.
Janet Egan is an adjunct senior fellow with the Technology and National Security Program at the Center for a New American Security.
More from CNAS
-
Technology & National Security
The AGI MomentIntroduction The age of AI is upon us. What that means is not yet clear. As general-purpose AI capabilities continue to march toward human-level performance across a range of ...
By Paul Scharre
-
Technology & National Security
CNAS Insights | America Must Expand AI Export Controls Amid Talks with ChinaThe path forward is to lengthen the United States’ AI lead by expanding, not weakening, technology protections, starting with closing three priority gaps: remote access, adver...
By Michelle Nie & Daniel Remler
-
Indo-Pacific Security / Technology & National Security
Sharper: China's AI RiseArtificial intelligence has become a strategic priority for Beijing and Washington, yet both countries continue to pursue dramatically different strategies in their bid for gl...
By Charles Horn & Cadence Barker
-
Technology & National Security
UN, Red Cross Call for Rules on Fully Autonomous WeaponsPaul Scharre, executive vice president at the Center for a New American Security, joins CNN to discuss the advent of fully autonomous weapons, the dangers of handing over targ...
By Paul Scharre
